roundupwp Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with roundupwp products.
Products
- registrations_for_the_events_calendar3 vulnerabilities
- Registrations for the Events Calendar – Event Registration Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-13119MEDIUM | Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' ParameterThe Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identif… CWE-89Jul 23, 2026 | CVSS6.5v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7982CRITICAL | Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSSThe Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. CWE-79Nov 8, 2024 | CVSS9.6v3.1 | EPSS0.665% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24943CRITICAL | Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL InjectionThe Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection. | CVSS9.8v3.1 | EPSS7.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-24876MEDIUM | Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site ScriptingThe Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | CVSS6.1v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |