CVE-2025-0959

Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id

The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 129 live websites that are affected by CVE-2025-0959.

Run a Free Instant Scan




Affected Software

Product  Eventer
Category Wordpress Plugins
Vulnerable Domains129 live websites (100% of Eventer install base)
Vulnerable Versions
  • from 0 through 3.9.9.2
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-564 SQL Injection: Hibernate



Details

  • Published - Mar 7, 2025
  • Updated - Mar 7, 2025

Credits

  • Lucio Sá (finder)

Website Distribution by Country

Number of websites using CVE-2025-0959
United States49 websites



GB11 websites
Germany10 websites
Canada8 websites
Netherlands8 websites
France7 websites
Italy5 websites
Cyprus4 websites
Belgium3 websites
Spain3 websites

Website Distribution by TLD

Number of websites using CVE-2025-0959
.org35 websites
.com31 websites
.nl8 websites
.ca5 websites
.de5 websites
.it5 websites
.co.uk4 websites
.fr4 websites
.be3 websites
.es2 websites

Websites affected by CVE-2025-0959

Top websites that are affected by CVE-2025-0959. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.org United States***,***
****.org GB***,***
************.org United States*,***,***
*************.edu Canada*,***,***
**********.be Belgium*,***,***
*********.de Germany*,***,***
********.org United States*,***,***
*****.org United States*,***,***
*****************.nl Netherlands*,***,***
***********.org Vietnam*,***,***
See full domain list

FAQ

CVE-2025-0959 is SQL Injection: Hibernate in Eventer
A total of 129 websites have been identified as vulnerable to CVE-2025-0959, based on global website indexing conducted by WebTechSurvey.
The Eventer is affected by the CVE-2025-0959 vulnerability.
Eventer versions up to and including 3.9.9.2 are vulnerable to CVE-2025-0959.