CVE · High

CVE-2024-11260 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 6.6.4 6.6.4 2025-02-20

CVE-2024-11260

The Events Manager plugin for WordPress versions up to 6.6.3 contains a time-based SQL injection flaw in the active_status parameter that allows unauthenticated attackers to execute arbitrary SQL queries. The vulnerability stems from inadequate escaping of user input and improper query preparation, enabling attackers to extract sensitive database information by injecting malicious SQL code into existing queries.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.