CVE-2014-8586 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 40.1% (pctl 99)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 40.09% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-11-04 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| cp multi view event calendar project | cp multi view event calendar |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection | 2014-10-27 |
References
- http://osvdb.org/show/osvdb/113670
- http://packetstormsecurity.com/files/128814/WordPress-CP-Multi-View-Event-Calendar-1.01-SQL-Injection.html
- http://www.exploit-db.com/exploits/35073
- http://www.securityfocus.com/bid/70718
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97766
- http://osvdb.org/show/osvdb/113670
- http://packetstormsecurity.com/files/128814/WordPress-CP-Multi-View-Event-Calendar-1.01-SQL-Injection.html
- http://www.exploit-db.com/exploits/35073
- http://www.securityfocus.com/bid/70718
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97766
→ the Explorer · watch your stack · NVD