CVE Database /
CVE-2024-11260
CVE · High
CVE-2024-11260 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-11260
|
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.5
|
< 6.6.4
|
6.6.4 |
2025-02-20 |
—
|
CVE-2024-11260
The Events Manager plugin for WordPress versions up to 6.6.3 contains a time-based SQL injection flaw in the active_status parameter that allows unauthenticated attackers to execute arbitrary SQL queries. The vulnerability stems from inadequate escaping of user input and improper query preparation, enabling attackers to extract sensitive database information by injecting malicious SQL code into existing queries.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings