plugin

Event Registration Vulnerabilities

13 known security issues reported for the Event Registration WordPress plugin. Most recent disclosed Jul 29, 2016.

3 critical 1 high

Running Event Registration on your site? Check whether your installed version is affected.

Scan your site free

Event Registration [event-registration] < 6.02.03 (closed)

unknown

This plugin is prone to SQL injection and stored cross site scripting vulnerabilities. Update the plugin.

Affected:
up to 6.02.03
Fixed in:
6.02.03
Disclosed:
Jul 29, 2016

Event Registration <= 6.02.02 - PHP Object Injection

critical

The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02.02 via deserialization of untrusted input from the 'reg_form' or 'questions' parameter. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin....

CVSS:
9.8
Affected:
up to 6.02.02
Fixed in:
6.03.01
Disclosed:
May 9, 2016

Event Registration <= 6.02.02 - SQL Injection

critical

The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘qanda’ parameters in versions up to, and including, 6.02.02 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
9.8
Affected:
up to 6.02.02
Fixed in:
6.03.01
Disclosed:
May 9, 2016

Event Registration <= 6.02.02 - Unauthenticated Stored Cross-Site Scripting

high

The Event Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attendees first and last name parameters in versions up to, and including, 6.02.02 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
7.2
Affected:
up to 6.02.02
Fixed in:
6.03.01
Disclosed:
May 9, 2016

Event Registration [event-registration] < 6.03.01

unknown

The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02.02 via deserialization of untrusted input from the 'reg_form' or 'questions' parameter. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin....

Affected:
up to 6.03.01
Fixed in:
6.03.01
Disclosed:
May 9, 2016

Event Registration [event-registration] < 6.03.01

unknown

The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘qanda’ parameters in versions up to, and including, 6.02.02 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

Affected:
up to 6.03.01
Fixed in:
6.03.01
Disclosed:
May 9, 2016

Event Registration [event-registration] < 6.03.01

unknown

The Event Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attendees first and last name parameters in versions up to, and including, 6.02.02 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 6.03.01
Fixed in:
6.03.01
Disclosed:
May 9, 2016

Event Registration [event-registration] < 6.00.03 (closed)

unknown

[en] SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.

Affected:
up to 6.00.03
Fixed in:
6.00.03
Disclosed:
Sep 13, 2011

CVE-2010-4839 on NVD →

Event Registration [event-registration] < 5.4.4 (closed)

unknown

Event Registration plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 5.4.4
Fixed in:
5.4.4
Disclosed:
Aug 30, 2011

Event Registration < 6.00.03 - SQL Injection

critical

SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.

CVSS:
9.8
Affected:
up to 6.00.03
Fixed in:
6.00.03
Disclosed:
Nov 15, 2010

CVE-2010-4839 on NVD →

Event Registration [event-registration] <= 6.02.02 (unfixed + closed)

unknown

The event-registration WordPress plugin was affected by a SQL Injection &amp; Stored XSS security vulnerability.

Affected:
up to 6.02.02
Fix:
No patched version reported

Event Registration [event-registration] <= 5.43 (unfixed + closed)

unknown

The event-registration WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 5.43
Fix:
No patched version reported

Event Registration [event-registration] <= 5.44 (unfixed + closed)

unknown
Affected:
up to 5.44
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database