Record summary

CVE-2021-24943 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 8, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Registrations for the Events Calendar – Event Registration Plugin

CVE List2.7.6 to < 2.7.6affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALRegistrations for the Events Calendar < 2.7.6 - SQL InjectionCVSS 9.8

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

Impact

Unauthenticated attackers can execute SQL injection through the event_id parameter, potentially extracting all Events Calendar registration data including attendee information.

Remediation

Fixed in 2.7.6

WeaknessesCWE-89
Authorsritikchaddha
Template tagstime-based-sqliwpscancvecve2021wpwp-pluginwordpresssqliregistrations-for-the-events-calendarroundupwpvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:roundupwp:registrations_for_the_events_calendar:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/registrations-for-the-events-calendar/
FOFA: body=/wp-content/plugins/registrations-for-the-events-calendar/

Source: ProjectDiscovery

References

2