Vulnerabilities > Simple Events Calendar Project

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2021-24552 SQL Injection vulnerability in Simple Events Calendar Project Simple Events Calendar
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue
network
low complexity
simple-events-calendar-project CWE-89
6.5