SQL Injection Vulnerability in Events Manager Plugin for WordPress
CVE-2024-11260
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 February 2025
What is CVE-2024-11260?
The Events Manager plugin for WordPress exhibits a time-based SQL Injection vulnerability due to improper handling of the active_status parameter across all versions up to and including 6.6.3. This flaw allows unauthenticated attackers to craft malicious inputs that can manipulate existing SQL queries. Consequently, attackers can potentially retrieve sensitive information from the database, exposing vulnerabilities that could be exploited for further malicious activities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Events Manager β Calendar, Bookings, Tickets, and more! * <= 6.6.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved