WordPress RSVPMarker Plugin <= 10.6.6 is vulnerable to Remote Code Execution (RCE)
CVE-2023-25054

10CRITICAL

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
29 December 2023

Summary

A vulnerability has been identified in RSVPMaker, developed by David F. Carr, allowing for improper control of the generation of code, also known as a code injection flaw. This issue opens the door for potential remote code execution, posing significant risks to users who have versions from n/a to 10.6.6. It is crucial for users to understand the implications of this vulnerability and to apply necessary updates to protect their systems.

Affected Version(s)

RSVPMaker <= 10.6.6

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ravi Dharmawan (Patchstack Alliance)
.