davidfcarr Vulnerabilities and Affected Products
Vulnerabilities associated with RSVPMarker.
Products
Clear product- RSVPMarker5 vulnerabilities
- Quick Playground3 vulnerabilities
- RSVPMaker3 vulnerabilities
- My Marginalia1 vulnerability
- RSVPMaker for Toastmasters1 vulnerability
- RSVPMaker Volunteer Roles1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-48278HIGH | WordPress RSVPMarker plugin <= 11.5.6 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.5.6. CWE-89May 19, 2025 | CVSS8.5v3.1 | EPSS0.301% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-31552CRITICAL | WordPress RSVPMarker plugin <= 11.6.7 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.6.7. CWE-89Apr 1, 2025 | CVSS9.3v3.1 | EPSS0.491% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24600MEDIUM | WordPress RSVPMaker plugin <= 11.4.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5. CWE-862Jan 27, 2025 | CVSS5.3v3.1 | EPSS0.288% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50531CRITICAL | WordPress RSVPMaker for Toastmasters plugin <= 6.2.4 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4. CWE-434Nov 4, 2024 | CVSS10.0v3.1 | EPSS0.511% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41652HIGH | WordPress RSVPMarker Plugin <= 10.6.6 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6. CWE-89Nov 3, 2023 | CVSS8.2v3.1 | EPSS0.862% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |