CVE-2017-14760: Eventespresso Event Espresso Lite

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.

Affected products

  • Eventespresso Event Espresso Lite: up to and including 3.1.37.12.l

Published 2017-09-27. Last modified 2026-06-17.