Event Registration [event-registration] < 6.02.03 (closed)
unknownThis plugin is prone to SQL injection and stored cross site scripting vulnerabilities. Update the plugin.
- Affected:
- up to 6.02.03
- Fixed in:
- 6.02.03
- Disclosed:
- Jul 29, 2016
plugin
13 known security issues reported for the Event Registration WordPress plugin. Most recent disclosed Jul 29, 2016.
Running Event Registration on your site? Check whether your installed version is affected.
Scan your site freeThis plugin is prone to SQL injection and stored cross site scripting vulnerabilities. Update the plugin.
The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02.02 via deserialization of untrusted input from the 'reg_form' or 'questions' parameter. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin....
The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘qanda’ parameters in versions up to, and including, 6.02.02 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...
The Event Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attendees first and last name parameters in versions up to, and including, 6.02.02 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02.02 via deserialization of untrusted input from the 'reg_form' or 'questions' parameter. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin....
The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘qanda’ parameters in versions up to, and including, 6.02.02 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...
The Event Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attendees first and last name parameters in versions up to, and including, 6.02.02 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
[en] SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.
Event Registration plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.
The event-registration WordPress plugin was affected by a SQL Injection & Stored XSS security vulnerability.
The event-registration WordPress plugin was affected by a SQL Injection security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free