CVE-2017-14760: Eventespresso Event Espresso Lite
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.
Affected products
- Eventespresso Event Espresso Lite: up to and including 3.1.37.12.l
Published 2017-09-27. Last modified 2026-06-17.