SQL Injection Vulnerability in Event Expresso Free v3.1.37.11.L WordPress Plugin

SQL Injection Vulnerability in Event Expresso Free v3.1.37.11.L WordPress Plugin

CVE-2017-1002026 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.

Learn more about our Wordpress Pen Testing.