WordPress RSVPMarker Plugin <= 10.6.6 is vulnerable to Remote Code Execution (RCE)
CVE-2023-25054
10CRITICAL
Summary
A vulnerability has been identified in RSVPMaker, developed by David F. Carr, allowing for improper control of the generation of code, also known as a code injection flaw. This issue opens the door for potential remote code execution, posing significant risks to users who have versions from n/a to 10.6.6. It is crucial for users to understand the implications of this vulnerability and to apply necessary updates to protect their systems.
Affected Version(s)
RSVPMaker <= 10.6.6
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ravi Dharmawan (Patchstack Alliance)