https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eventon/eventon-wordpress-virtual-event-calendar-plugin-5011-unauthenticated-blind-sql-injection-via-search-parameter
- Jul 1,2026 AT 9:20AM - 1 month agoHello,
Thank you for your messages!
I am going to escalate this ticket to development to help in here. Please allow us some time to address this, and we truly appreciate your patience. Thank you for being a valued EventON customer!
the critical security vulnerability has been made known to the public for over 2 days now – any advice?
Hello
I am also concerned about this critical security breach.
Is public deactivation of the search field a reliable mitigation measure?
Regards
Hello,
We are working on the issue and will update you all ASAP.
Yes, agreed. Will this be fixed today? As others have said, this has been public for 2 days now. I had thought it would have been reolved by now. What are we supposed to do? Use an old version? …or just leave this risk open
Thank you for letting us know of this and we are working on get this resolved ASAP and getting a new update out soon!
We’ve just released 5.0.12 that fixes the issue. Please update ASAP.
Latest version will address this issue and the wordfence database should be updated soon to reflect this.