Events For Geodirectory
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-39532 | Hig | 0.50 | 8.8 | 0.00 | Jun 15, 2026 | Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions. | ||
| CVE-2026-11616 | Hig | 0.50 | 8.8 | 0.00 | Jun 9, 2026 | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled… |
- risk 0.50cvss 8.8epss 0.00
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
- risk 0.50cvss 8.8epss 0.00
The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled…