Showing 1 vulnerability on this page for Registrations for the Events Calendar – Event Registration Plugin

Signals CISA KEV Ransomware Nuclei
roundupwp vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identif

CWE-89Jul 23, 2026
CVSS6.5v3.1EPSS0.249%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX