← back
CVE-2022-1905CWE-89

Events Made Easy < 2.2.81 - Unauthenticated SQLi

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 37%
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection