CVE-2017-7719: Web-Dorado Spider Event Calendar

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.

Affected products

  • Web-Dorado Spider Event Calendar: up to and including 1.5.51

Published 2017-04-12. Last modified 2026-06-17.