The Event Manager and Tickets Selling for WooCommerce...
High severity
Unreviewed
Published
Mar 15, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 14, 2022
Published to the GitHub Advisory Database
Mar 15, 2022
Last updated
Jan 27, 2023
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
References