Unauthorized Access in RSVP and Event Management Plugin for WordPress
CVE-2024-12711

5.3MEDIUM

Key Information:

Vendor
WPchill
Status
Rsvp And Event Management
Vendor
CVE Published:
7 January 2025

Summary

The RSVP and Event Management plugin for WordPress is susceptible to unauthorized access due to an oversight in the implementation of capability checks within key AJAX functions, including bulk_delete_attendees() and bulk_delete_questions(). All versions up to and including 2.7.13 are affected. This flaw enables unauthenticated attackers to delete attendees and questions, while authenticated users may improperly alter question menu orders, compromising the integrity and security of event management functionalities.

Affected Version(s)

RSVP and Event Management * <= 2.7.13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.