Executive brief
The Events Manager is a popular WordPress plugin for managing events, calendars, and ticket bookings. The plugin contains a second-order SQL injection vulnerability that allows authenticated users with contributor access or higher to extract sensitive database information by injecting malicious SQL through custom event or location meta fields and then triggering the duplicate function. This could expose customer data, user credentials, or other confidential information stored in the WordPress database.
Technical details
The vulnerability is a second-order SQL injection in the event_duplicate and location_duplicate actions. An attacker with contributor-level or higher permissions first inserts SQL metacharacters into a custom meta key via WordPress's standard add-meta flow (which stores the data verbatim in wp_postmeta). When the event or location is duplicated, the plugin reads the stored meta keys via get_post_meta() and concatenates them directly into an INSERT query without proper escaping or parameterization. The lack of prepared statements on the existing SQL query allows the attacker to append arbitrary SQL commands. This affects all versions up to and including 7.4.0 and requires authentication and contributor-level access, but no user interaction beyond triggering the duplicate action.
Affected products
- The Events Manager The Events Manager up to and including 7.4.0
Timeline
- 2026-08-25: disclosed