Showing 3 vulnerabilities on this page for RSVPMaker

Signals CISA KEV Ransomware Nuclei
davidfcarr vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

RSVPMaker <= 9.3.2 - Unauthenticated SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

CWE-89Jun 13, 20221 related artifact
CVSS9.8v3.1EPSS12.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

RSVPMaker <= 9.2.6 - Unauthenticated SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.

CWE-89May 10, 2022
CVSS9.8v3.1EPSS1.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

RSVPMaker <= 9.2.5 - Unauthenticated SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

CWE-89May 10, 20221 related artifact
CVSS9.8v3.1EPSS7.16%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX