SQL Injection Vulnerability in imithemes Eventer Plugin
CVE-2025-39481
9.8CRITICAL
What is CVE-2025-39481?
The imithemes Eventer plugin for WordPress is susceptible to a SQL Injection vulnerability that allows an attacker to execute blind SQL queries. This flaw can lead to unauthorized data access and manipulation, compromising the security of the database. The affected versions range from n/a through 3.9.6, making it essential for users of the Eventer plugin to apply necessary patches to mitigate the associated risks.
Affected Version(s)
Eventer <= 3.9.6