Record summary

CVE-2022-1453 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 31, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 9.2.5affected

Nuclei templates

1
ProjectDiscoveryCRITICALRSVPMaker <= 9.2.5 - SQL InjectionCVSS 9.8

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

Impact

Attackers can retrieve sensitive data from the database without authentication, leading to data breach and privacy violations.

Remediation

Update to version 9.2.6, or later

WeaknessesCWE-89
AuthorsShivam Kamboj
Template tagscvecve2022wordpresswpwp-pluginsqlirsvpmakervkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

5