A high severity vulnerability, CVE‑2025‑6970, has been identified in the WordPress plugin Events Manager, all versions up to and including 7.0.3. This flaw is a time‑based SQL injection in the “orderby” parameter, arising from insufficient escaping and improper query preparation, allowing unauthenticated attackers to inject SQL commands and extract sensitive database data remotely. With over 100,000 active websites using the Events Manager plugin, the potential exposure is significant. The IONIX research team validated the impact through successful exploit reproduction, as detailed in this advisory.
References:

