SQL Injection Vulnerability in Roundup WP Registrations for the Events Calendar
CVE-2024-39638
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 29 August 2024
Summary
A SQL Injection vulnerability exists in the Roundup WP Registrations plugin for the Events Calendar, allowing attackers to manipulate SQL queries by exploiting improper neutralization of special elements within input data. This vulnerability impacts Registrations for the Events Calendar from any version up to 2.12.2. If successfully exploited, it could lead to unauthorized access to sensitive data, potentially compromising the underlying database's integrity, thus endangering user information and the overall security of affected WordPress installations.
Affected Version(s)
Registrations for the Events Calendar <= 2.12.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc / truonghuuphuc (Patchstack Alliance)