Sensitive Data Exposure in WP Chill RSVP and Event Management Plugin
CVE-2026-39536

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39536?

A weakness has been identified in the WP Chill RSVP and Event Management plugin, which could allow unauthorized access to sensitive system information. This vulnerability enables an attacker to retrieve embedded sensitive data, potentially compromising the confidentiality of the affected system. The issue impacts versions up to and including 2.7.16, highlighting the importance for users to update their installations to safeguard against potential exploitation.

Affected Version(s)

RSVP and Event Management 0 <= 2.7.16

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Sharief | Patchstack Bug Bounty Program
.