CVE-2017-7719

Publication date

2017-04-12 15:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.