← Back to browse · API

CVE-2022-1505

Severity
CRITICAL
CVSS
9.8
EPSS
0.01795
Risk score
39.83
CISA KEV
No
PoC
No
Published
2022-05-10
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2022-24805, GHSA-6H3G-G32R-8FF5
Products
davidfcarr:RSVPMaker 0 ≤9.2.6
Sources
euvd EUVD-2022-24805

Description

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.

References