Description
WordPress Plugin Events Manager Extended is prone to an SQL injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database. WordPress Plugin Events Manager Extended version 3.1.2 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin Adminimize 'page' Parameter Cross-Site Scripting (1.7.21)
WordPress Plugin Contact Form 7 Arbitrary File Upload (3.5.3)
WordPress Plugin Simple Membership SQL Injection (4.0.3)
WordPress Plugin RokMicroNews Multiple Vulnerabilities (1.5)
WordPress Plugin Uploader Cross-Site Scripting and Arbitrary File Upload Vulnerabilities (1.0.4)