SQL Injection Vulnerability in Roundup WP Registrations for the Events Calendar
CVE-2024-39638
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 August 2024
What is CVE-2024-39638?
A SQL Injection vulnerability exists in the Roundup WP Registrations plugin for the Events Calendar, allowing attackers to manipulate SQL queries by exploiting improper neutralization of special elements within input data. This vulnerability impacts Registrations for the Events Calendar from any version up to 2.12.2. If successfully exploited, it could lead to unauthorized access to sensitive data, potentially compromising the underlying database's integrity, thus endangering user information and the overall security of affected WordPress installations.
Affected Version(s)
Registrations for the Events Calendar <= 2.12.2