Critical severity9.8NVD Advisory· Published Sep 27, 2017· Updated May 13, 2026
CVE-2017-14760
CVE-2017-14760
Description
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.
Affected products
1- cpe:2.3:a:eventespresso:event_espresso_lite:*:*:*:*:*:wordpress:*:*Range: <=3.1.37.12.l
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.sstrunk.com/cve/wp_event-espresso-free.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.