Important Security Update – 7.4.7

We’ve received reports of a recently disclosed SQL injection vulnerability in Events Manager, and have released version 7.4.7 with a fix within 24 hours. This is a serious vulnerability that has gone undetected since version 7.3, so if your site is running anything from 7.3 to 7.4.6, please update as soon as you can.

What happened

The flaw sat in some older code that validates the dates of an event search. That code wasn’t reachable in a harmful way through the regular front-end search, but the REST API we introduced in 7.3 passes search parameters along differently, which let a specially crafted request get past the validation and into a database query.

Exploiting it requires being logged in, although any account will do, right down to a basic Subscriber.

What to do

Update Events Manager to 7.4.7. That closes the vulnerability on its own, whichever version of Events Manager Pro you’re running (or if you don’t use Pro at all).

At the time of writing, 7.4.7 is sitting in a roughly 5-hour queue before WordPress.org offers it to sites, as part of the Protect The Shire initiative, which holds every new plugin release for a few hours, security fixes included. We’ve asked the Plugins team to speed this one up, but you don’t have to wait for them. Follow our instructions to getting the latest stable update (whicn you can enable automatically) via our settings page, or update to a dev version, which is also on 7.4.7.

On older versions that option isn’t available yet… instead, download the 7.4.7 zip from the plugin page and upload it from the Plugins screen (Add New, then Upload Plugin), which replaces your installed copy.

If you use Pro, please also update to Pro 3.9.5. Pro’s own REST API, added in 3.8.1, offered a second route to the same flaw for users who can manage bookings. Events Manager 7.4.7 already closes that route, and Pro 3.9.5 hardens Pro’s code as well, so it no longer relies on the core fix alone.

Credit for the discovery goes to neurotx, who disclosed it via Patchstack.

More eyes, stronger plugin

We’ve put Events Manager through several AI-assisted security audits this year, which turned up and fixed a number of issues, and this one still slipped past every pass. It goes to show that different researchers using different tools will sometimes uncover what everyone else missed. It’s regrettable that older code was the source of this one, and we’re sorry for the hassle of an urgent update… but we also appreciate having so many eyes on an open source plugin like this. That attention is what lets us put Events Manager through the gauntlet of rigorous security testing and harden it properly, and the result is a stronger plugin for everyone. We’re all for it.

On a ligter note

We’ve brought back our recent Pro promotion for a little longer, as a thank you to everyone who has stuck with us and anyone joining now. It’s entirely separate from this fix, which is free for everyone in Events Manager 7.4.7, whether or not you use Pro.

Changelog

Events Manager 7.4.7

  • Security: Fixed an authenticated SQL injection vulnerability in the REST API events and bookings search, disclosed by neurotx via Patchstack.

Events Manager Pro 3.9.5

  • Security: Hardened the coupons date-scope search against SQL injection, scope dates are now validated before use.
  • Fixed: Timeslot bookings in the Multiple Bookings cart could not show their details or be removed, the cart script did not escape the event:timeslot id in its selectors

Leave a Reply

Your email address will not be published. Required fields are marked *