SQL Injection Vulnerability in Roundup WP Registrations for the Events Calendar
CVE-2024-39638

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
29 August 2024

Summary

A SQL Injection vulnerability exists in the Roundup WP Registrations plugin for the Events Calendar, allowing attackers to manipulate SQL queries by exploiting improper neutralization of special elements within input data. This vulnerability impacts Registrations for the Events Calendar from any version up to 2.12.2. If successfully exploited, it could lead to unauthorized access to sensitive data, potentially compromising the underlying database's integrity, thus endangering user information and the overall security of affected WordPress installations.

Affected Version(s)

Registrations for the Events Calendar <= 2.12.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc / truonghuuphuc (Patchstack Alliance)
.