plugin

Registrations For The Events Calendar Vulnerabilities

15 known security issues reported for the Registrations For The Events Calendar WordPress plugin. Most recent disclosed Jul 22, 2026.

2 critical 1 high 5 medium

Running Registrations For The Events Calendar on your site? Check whether your installed version is affected.

Scan your site free

Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter

medium

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys dire...

CVSS:
6.5
Affected:
up to 3.2
Fixed in:
3.2.1
Disclosed:
Jul 22, 2026

CVE-2026-13119 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.13.4

unknown

[en] The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.13.4
Fixed in:
2.13.4
Disclosed:
Mar 25, 2025

CVE-2024-10703 on NVD →

Registrations for the Events Calendar <= 2.13.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adm...

CVSS:
4.4
Affected:
up to 2.13.3
Fixed in:
2.13.4
Disclosed:
Mar 3, 2025

CVE-2024-10703 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.12.4

unknown

[en] The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

Affected:
up to 2.12.4
Fixed in:
2.12.4
Disclosed:
Nov 8, 2024

CVE-2024-7982 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.12.2

unknown

[en] Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1.

Affected:
up to 2.12.2
Fixed in:
2.12.2
Disclosed:
Nov 1, 2024

CVE-2024-43143 on NVD →

Registrations for the Events Calendar – Event Registration Plugin <= 2.12.3 - Unauthenticated Stored Cross-Site Scripting

high

The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name parameters in all versions up to, and including, 2.12.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
7.2
Affected:
up to 2.12.3
Fixed in:
2.12.4
Disclosed:
Oct 18, 2024

CVE-2024-7982 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.12.3

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2.

Affected:
up to 2.12.3
Fixed in:
2.12.3
Disclosed:
Aug 29, 2024

CVE-2024-39638 on NVD →

Registrations for the Events Calendar <= 2.12.1 - Missing Authorization

medium

The Registrations for the Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtec_process_form_submission() and rtec_records_edit() functions in versions up to, and including, 2.12.1. This makes it possible for authenticated attackers, with c...

CVSS:
4.3
Affected:
up to 2.12.1
Fixed in:
2.12.2
Disclosed:
Aug 7, 2024

CVE-2024-43143 on NVD →

Registrations for the Events Calendar – Event Registration Plugin <= 2.12.2 - Authenticated (Contributor+) SQL Injection

critical

The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.12.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...

CVSS:
9.9
Affected:
up to 2.12.2
Fixed in:
2.12.3
Disclosed:
Jul 30, 2024

CVE-2024-39638 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.7.10

unknown

[en] The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.7.10
Fixed in:
2.7.10
Disclosed:
Jan 24, 2022

CVE-2021-25083 on NVD →

Registrations for the Events Calendar <= 2.7.9 - Reflected Cross-Site Scripting

medium

The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.7.10
Fixed in:
2.7.10
Disclosed:
Dec 27, 2021

CVE-2021-25083 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.7.6

unknown

[en] The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Dec 6, 2021

CVE-2021-24943 on NVD →

Registrations for the Events Calendar &#8211; Event Registration Plugin [registrations-for-the-events-calendar] < 2.7.5

unknown

[en] The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Nov 29, 2021

CVE-2021-24876 on NVD →

Registrations for the Events Calendar <= 2.7.5 - Unauthenticated SQL Injection

critical

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVSS:
9.8
Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Nov 8, 2021

CVE-2021-24943 on NVD →

Registrations for The Events Calendar <= 2.7.4 - Reflected Cross-Site Scripting

medium

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Oct 27, 2021

CVE-2021-24876 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database