Input validation vulnerability in Events Manager Pro 2.6.7.2

The Events Manager Pro and the Events Manager plugins for WordPress have versions up to 2.6.7.2 and 5.9.7.2 respectively, and these versions are vulnerable to CSV Injection. This means that unauthenticated attackers can insert malicious input into a CSV file that is then exported. If this file is downloaded and opened on a computer with a vulnerable configuration, the malicious code in the file could be executed.

Detected in:

Events Manager fixed vulnerable versions: >= * < 5.9.7.2
Events Manager Pro fixed vulnerable versions: >= * < 2.6.7.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.