Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter
medium
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys dire...
- CVSS:
- 6.5
- Affected:
- up to 3.2
- Fixed in:
- 3.2.1
- Disclosed:
- Jul 22, 2026
CVE-2026-13119 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.13.4
unknown
[en] The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.4
- Disclosed:
- Mar 25, 2025
CVE-2024-10703 on NVD →
Registrations for the Events Calendar <= 2.13.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adm...
- CVSS:
- 4.4
- Affected:
- up to 2.13.3
- Fixed in:
- 2.13.4
- Disclosed:
- Mar 3, 2025
CVE-2024-10703 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.12.4
unknown
[en] The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
- Affected:
- up to 2.12.4
- Fixed in:
- 2.12.4
- Disclosed:
- Nov 8, 2024
CVE-2024-7982 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.12.2
unknown
[en] Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1.
- Affected:
- up to 2.12.2
- Fixed in:
- 2.12.2
- Disclosed:
- Nov 1, 2024
CVE-2024-43143 on NVD →
Registrations for the Events Calendar – Event Registration Plugin <= 2.12.3 - Unauthenticated Stored Cross-Site Scripting
high
The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name parameters in all versions up to, and including, 2.12.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 7.2
- Affected:
- up to 2.12.3
- Fixed in:
- 2.12.4
- Disclosed:
- Oct 18, 2024
CVE-2024-7982 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.12.3
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2.
- Affected:
- up to 2.12.3
- Fixed in:
- 2.12.3
- Disclosed:
- Aug 29, 2024
CVE-2024-39638 on NVD →
Registrations for the Events Calendar <= 2.12.1 - Missing Authorization
medium
The Registrations for the Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtec_process_form_submission() and rtec_records_edit() functions in versions up to, and including, 2.12.1. This makes it possible for authenticated attackers, with c...
- CVSS:
- 4.3
- Affected:
- up to 2.12.1
- Fixed in:
- 2.12.2
- Disclosed:
- Aug 7, 2024
CVE-2024-43143 on NVD →
Registrations for the Events Calendar – Event Registration Plugin <= 2.12.2 - Authenticated (Contributor+) SQL Injection
critical
The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.12.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...
- CVSS:
- 9.9
- Affected:
- up to 2.12.2
- Fixed in:
- 2.12.3
- Disclosed:
- Jul 30, 2024
CVE-2024-39638 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.7.10
unknown
[en] The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 2.7.10
- Fixed in:
- 2.7.10
- Disclosed:
- Jan 24, 2022
CVE-2021-25083 on NVD →
Registrations for the Events Calendar <= 2.7.9 - Reflected Cross-Site Scripting
medium
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 2.7.10
- Fixed in:
- 2.7.10
- Disclosed:
- Dec 27, 2021
CVE-2021-25083 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.7.6
unknown
[en] The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Dec 6, 2021
CVE-2021-24943 on NVD →
Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] < 2.7.5
unknown
[en] The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Nov 29, 2021
CVE-2021-24876 on NVD →
Registrations for the Events Calendar <= 2.7.5 - Unauthenticated SQL Injection
critical
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
- CVSS:
- 9.8
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Nov 8, 2021
CVE-2021-24943 on NVD →
Registrations for The Events Calendar <= 2.7.4 - Reflected Cross-Site Scripting
medium
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.5
- Disclosed:
- Oct 27, 2021
CVE-2021-24876 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database