Input validation vulnerability in Eventify™ – Simple Events *-1.7.f

The Eventify – Simple Events plugin for WordPress is vulnerable to a type of attack called SQL Injection. This means that in versions up to and including 1.7.f, someone who is not authorized to access the database can tell the system to execute additional commands which could be used to extract sensitive information. In order to exploit this vulnerability, the setting ‘magic_quotes’ must be turned off.

Detected in:

Eventify™ – Simple Events open vulnerable versions: >= * <= 1.7.f

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.