← Back to browse · API

CVE-2022-1453

Severity
CRITICAL
CVSS
9.8
EPSS
0.07158
Risk score
41.71
CISA KEV
No
PoC
No
Published
2022-05-10
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2022-24759, GHSA-R8CV-3FJ5-M22G
Products
davidfcarr:RSVPMaker 0 ≤9.2.5
Sources
euvd EUVD-2022-24759

Description

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

References