CVE-2022-1453

CRITICAL EXPLOITED NUCLEI

Carrcommunications Rsvpmaker < 9.2.6 - SQL Injection

Title source: rule

Description

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

Nuclei Templates (1)

RSVPMaker <= 9.2.5 - SQL Injection
CRITICALVERIFIEDby Shivam Kamboj

Scores

CVSS v3 9.8
EPSS 0.6749
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-03-31
CWE
CWE-89
Status published
Products (2)
carrcommunications/rsvpmaker < 9.2.6
davidfcarr/RSVPMaker < 9.2.5
Published May 10, 2022
Tracked Since Feb 18, 2026