VYPR

The Events Calendar for GeoDirectory

by WordPress

CVEs (1)

  • CVE-2026-11616HigJun 9, 2026
    risk 0.50cvss 8.8epss

    The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled…