Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill RSVP and Event Management Plugin allows SQL Injection. This issue affects RSVP and Event Management Plugin: from n/a through 2.7.14.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-3877 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill RSVP and Event Management Plugin allows SQL Injection. This issue affects RSVP and Event Management Plugin: from n/a through 2.7.14.
Fixes

Solution

Update the WordPress RSVP and Event Management Plugin wordpress plugin to the latest available version (at least 2.7.15).


Workaround

No workaround given by the vendor.

History

Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill RSVP and Event Management Plugin allows SQL Injection. This issue affects RSVP and Event Management Plugin: from n/a through 2.7.14.
Title WordPress RSVP and Event Management Plugin <= 2.7.14 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-02-12T20:01:18.418Z

Reserved: 2025-01-23T14:52:14.007Z

Link: CVE-2025-24683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-24T18:15:42.133

Modified: 2025-01-24T18:15:42.133

Link: CVE-2025-24683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses