CVE-2020-35012

CVE-2020-35012: Events Manager < 5.9.8 - Admin+ SQL Injection

Vendor Unknown
Product Events Manager
Weakness CWE-89 · SQLi
Published December 1, 2021
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

Key dates

02Disclosure timeline

December 1, 2021 CVE published
August 4, 2024 Record updated