RSVP and Event Management <= 2.7.16 - Missing Authorization
medium
The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.16. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.7.16
- Fixed in:
- 2.7.17
- Disclosed:
- May 25, 2026
CVE-2026-27398 on NVD →
RSVP and Event Management <= 2.7.16 - Unauthenticated Information Exposure
medium
The RSVP and Event Management plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.16. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.7.16
- Fixed in:
- 2.7.17
- Disclosed:
- Mar 12, 2026
CVE-2026-39536 on NVD →
RSVP and Event Management Plugin <= 2.7.14 - Authenticated (Administrator+) SQL Injection
medium
The RSVP and Event Management Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.9
- Affected:
- up to 2.7.14
- Fixed in:
- 2.7.15
- Disclosed:
- Jan 24, 2025
CVE-2025-24683 on NVD →
RSVP and Event Management [rsvp] < 2.7.15
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill RSVP and Event Management Plugin allows SQL Injection. This issue affects RSVP and Event Management Plugin: from n/a through 2.7.14.
- Affected:
- up to 2.7.15
- Fixed in:
- 2.7.15
- Disclosed:
- Jan 24, 2025
CVE-2025-24683 on NVD →
RSVP and Event Management [rsvp] < 2.7.14
unknown
[en] The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete q...
- Affected:
- up to 2.7.14
- Fixed in:
- 2.7.14
- Disclosed:
- Jan 7, 2025
CVE-2024-12711 on NVD →
RSVP and Event Management <= 2.7.13 - Missing Authorization
medium
The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questi...
- CVSS:
- 5.3
- Affected:
- up to 2.7.13
- Fixed in:
- 2.7.14
- Disclosed:
- Jan 6, 2025
CVE-2024-12711 on NVD →
RSVP and Event Management [rsvp] < 2.7.8
unknown
[en] The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user...
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Apr 18, 2022
CVE-2022-1054 on NVD →
RSVP and Event Management <= 2.7.7 - Unauthenticated Sensitive Information Disclosure
medium
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user regis...
- CVSS:
- 5.3
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.8
- Disclosed:
- Apr 11, 2022
CVE-2022-1054 on NVD →
RSVP and Event Management <= 2.7.4 - Cross-Site Scripting
medium
The RSVP and Event Management plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 13, 2022
RSVP and Event Management [rsvp] < 2.7.5
unknown
The RSVP and Event Management plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 13, 2022
RSVP and Event Management [rsvp] < 2.7.5
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress RSVP and Event Management plugin (versions <= 2.7.4).
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 12, 2022
RSVP and Event Management [rsvp] < 2.7.5
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress RSVP and Event Management plugin (versions <= 2.7.4). The vulnerability has some limitations in the case of high privilege users.
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 12, 2022
RSVP and Event Management [rsvp] < 2.3.8
unknown
[en] The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Aug 21, 2019
CVE-2017-18563 on NVD →
RSVP and Event Management Plugin <= 2.3.7 - Cross-Site Scripting
medium
The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen.
- CVSS:
- 6.1
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Jun 12, 2017
CVE-2017-18563 on NVD →
RSVP and Event Management [rsvp] < 2.7.5
unknown
The plugin does not sanitise and escape various parameters before outputting them back in attributes in admin pages, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database