Unauthorized Access in RSVP and Event Management Plugin for WordPress
CVE-2024-12711
5.3MEDIUM
What is CVE-2024-12711?
The RSVP and Event Management plugin for WordPress is susceptible to unauthorized access due to an oversight in the implementation of capability checks within key AJAX functions, including bulk_delete_attendees() and bulk_delete_questions(). All versions up to and including 2.7.13 are affected. This flaw enables unauthenticated attackers to delete attendees and questions, while authenticated users may improperly alter question menu orders, compromising the integrity and security of event management functionalities.
Affected Version(s)
RSVP and Event Management * <= 2.7.13