Extension WordPress

Vulnérabilités RSVPMaker

Cette page rassemble les failles publiées pour RSVPMaker, leurs plages de versions affectées et les correctifs signalés dans la base locale.

17Vulnérabilités
8Critiques
17Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de RSVPMaker

17 fiches

CVE-2025-24600 Moyenne · 5,3
RSVPMaker

RSVPMarker <= 11.4.5 – Missing Authorization

The RSVPMaker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 11.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized…

Versions affectées

*-11.4.5

Correctif

11.4.6

Publication

24/01/2025

CVE-2023-27617 Moyenne · 4,4
RSVPMaker

RSVPMarker <= 10.6.5 – Authenticated (Administrator+) Stored Cross-Site Scripting via admin settings

The RSVPMarker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 10.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-10.6.5

Correctif

10.6.7

Publication

17/08/2023

CVE-2022-1768 Critique · 9,8
RSVPMaker

RSVPMaker <= 9.3.2 – Unauthenticated SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to…

Versions affectées

*-9.3.2

Correctif

9.3.3

Publication

17/05/2022

CVE-2022-1505 Critique · 9,8
RSVPMaker

RSVPMaker <= 9.2.6 – Unauthenticated SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers…

Versions affectées

*-9.2.6

Correctif

9.2.7

Publication

27/04/2022

CVE-2022-1453 Critique · 9,8
RSVPMaker

RSVPMaker <= 9.2.5 – Unauthenticated SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers…

Versions affectées

*-9.2.5

Correctif

9.2.6

Publication

26/04/2022

CVE-2021-24371 Faible · 2,7
RSVPMaker

RSVPMaker <= 8.7.2 – Server-Side Request Forgery

The Import feature of the RSVPMaker WordPress plugin before 8.7.4 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could…

Versions affectées

[*, 8.7.3)

Correctif

8.7.4

Publication

29/06/2021

CVE-2019-15646 Critique · 9,8
RSVPMaker

RSVPMaker <= 6.1.9 – SQL Injection

The RSVPMaker plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 6.1.9 due to insufficient escaping on a user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-6.1.9

Correctif

6.2

Publication

28/04/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités