CVE-2020-35012: Pixelite Events Manager

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

Affected products

  • Pixelite Events Manager: before 5.9.8 (fixed in 5.9.8)

Published 2021-12-01. Last modified 2026-06-17.