CVE-2017-1002026: Eventespresso Event Espresso
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.
Affected products
- Eventespresso Event Espresso: version 3.1.37.11.l only
Published 2017-09-14. Last modified 2026-06-17.