roundupwp Vulnerabilities and Affected Products
Vulnerabilities associated with Registrations for the Events Calendar – Event Registration Plugin.
Products
Clear product- registrations_for_the_events_calendar3 vulnerabilities
- Registrations for the Events Calendar – Event Registration Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-13119MEDIUM | Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' ParameterThe Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identif… CWE-89Jul 23, 2026 | CVSS6.5v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |