9.3
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Description
The Events Calendar SQL Injection CVE-2026-49772 PoC Description CVE-2026-49772 is an unauthenticated blind SQL injection in the WordPress plugin The Events Calendar. A broken REST parameter validator validatecallback returns a closure instead of...
Basic Information
ID
4DC88245-D5D6-582C-AA2B-EE9293E136F3
Published
Jun 22, 2026 at 21:02
Modified
Jun 22, 2026 at 21:07