VendorsEvent List Projectevent_listall versions
Vulnerabilities

Event List Project Event List

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-9429
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.
Published 2017-06-13 · Modified
8.81 PoCEPSS 0.027
CVE-2017-12068
The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categories delete_bulk action.
Published 2017-08-01 · Modified
6.1EPSS 0.008
CVE-2022-0418
Event List < 0.8.8 - Admin+ Stored Cross-Site Scripting
Published 2022-05-02 · Modified
4.8EPSS 0.006