plugin

Rsvpmaker Vulnerabilities

39 known security issues reported for the Rsvpmaker WordPress plugin. Most recent disclosed May 19, 2025.

8 critical 5 high 3 medium 1 low

Running Rsvpmaker on your site? Check whether your installed version is affected.

Scan your site free

RSVPMarker <= 11.5.6 - Authenticated (Contributor+) SQL Injection

medium

The RSVPMarker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.5.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and ab...

CVSS:
6.5
Affected:
up to 11.5.6
Fixed in:
11.5.7
Disclosed:
May 19, 2025

CVE-2025-48278 on NVD →

RSVPMaker [rsvpmaker] < 11.5.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker allows SQL Injection. This issue affects RSVPMarker : from n/a through 11.5.6.

Affected:
up to 11.5.7
Fixed in:
11.5.7
Disclosed:
May 19, 2025

CVE-2025-48278 on NVD →

RSVPMaker [rsvpmaker] <= 11.5.5 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker allows SQL Injection. This issue affects RSVPMarker : from n/a through 11.4.8.

Affected:
up to 11.5.5
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31552 on NVD →

RSVPMarker <= 11.6.7 - Unauthenticated SQL Injection

high

The RSVPMarker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries in...

CVSS:
7.5
Affected:
up to 11.6.7
Fixed in:
11.6.8
Disclosed:
Mar 31, 2025

CVE-2025-31552 on NVD →

RSVPMaker [rsvpmaker] < 11.4.6

unknown

[en] Missing Authorization vulnerability in David F. Carr RSVPMarker . This issue affects RSVPMarker : from n/a through 11.4.5.

Affected:
up to 11.4.6
Fixed in:
11.4.6
Disclosed:
Jan 27, 2025

CVE-2025-24600 on NVD →

RSVPMarker <= 11.4.5 - Missing Authorization

medium

The RSVPMaker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 11.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 11.4.5
Fixed in:
11.4.6
Disclosed:
Jan 24, 2025

CVE-2025-24600 on NVD →

RSVPMaker [rsvpmaker] < 10.6.7

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6.

Affected:
up to 10.6.7
Fixed in:
10.6.7
Disclosed:
Dec 29, 2023

CVE-2023-25054 on NVD →

RSVPMaker [rsvpmaker] < 10.6.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.

Affected:
up to 10.6.7
Fixed in:
10.6.7
Disclosed:
Nov 3, 2023

CVE-2023-41652 on NVD →

RSVPMaker [rsvpmaker] < 9.9.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.

Affected:
up to 9.9.4
Fixed in:
9.9.4
Disclosed:
Oct 31, 2023

CVE-2023-25045 on NVD →

RSVPMaker [rsvpmaker] < 9.9.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.

Affected:
up to 9.9.4
Fixed in:
9.9.4
Disclosed:
Oct 31, 2023

CVE-2023-25047 on NVD →

RSVPMaker [rsvpmaker] < 10.6.7

unknown

[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.

Affected:
up to 10.6.7
Fixed in:
10.6.7
Disclosed:
Sep 27, 2023

CVE-2023-27616 on NVD →

RSVPMaker [rsvpmaker] < 10.6.7

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.

Affected:
up to 10.6.7
Fixed in:
10.6.7
Disclosed:
Sep 27, 2023

CVE-2023-27617 on NVD →

RSVPMaker <= 10.6.6 - Unauthenticated PHP Object Injection

critical

The RSVPMaker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 10.6.6 via deserialization of untrusted input from the $details variable. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present v...

CVSS:
9.8
Affected:
up to 10.6.6
Fixed in:
10.6.7
Disclosed:
Sep 5, 2023

CVE-2023-25054 on NVD →

RSVPMarker <= 10.6.6 - Unauthenticated SQL Injection

critical

The RSVPMarker plugin for WordPress is vulnerable to SQL Injection via the 'email' parameter in versions up to, and including, 10.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append...

CVSS:
9.8
Affected:
up to 10.6.6
Fixed in:
10.6.7
Disclosed:
Sep 1, 2023

CVE-2023-41652 on NVD →

RSVPMaker <= 10.6.5 - Unauthenticated Stored Cross-Site Scripting via 'email'

high

The RSVPMaker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 10.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
7.2
Affected:
up to 10.6.5
Fixed in:
10.6.6
Disclosed:
Aug 17, 2023

CVE-2023-27616 on NVD →

RSVPMarker <= 10.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via admin settings

medium

The RSVPMarker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 10.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

CVSS:
4.4
Affected:
up to 10.6.5
Fixed in:
10.6.7
Disclosed:
Aug 17, 2023

CVE-2023-27617 on NVD →

RSVPMaker [rsvpmaker] < 10.5.5

unknown

[en] Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.

Affected:
up to 10.5.5
Fixed in:
10.5.5
Disclosed:
Jul 10, 2023

CVE-2023-29095 on NVD →

RSVPMaker <= 10.5.4 - Authenticated (Administrator+) SQL Injection via 'resend'

high

The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'resend' parameter in versions up to, and including, 10.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin...

CVSS:
7.2
Affected:
up to 10.5.5
Fixed in:
10.5.5
Disclosed:
Jul 5, 2023

CVE-2023-29095 on NVD →

RSVPMaker <= 9.9.3 - Authenticated (Admin+) SQL Injection via 'delete' parameter

high

The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'delete' parameter in versions up to, and including, 9.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for admin-level attackers to append additi...

CVSS:
7.2
Affected:
up to 9.9.3
Fixed in:
9.9.4
Disclosed:
Feb 13, 2023

CVE-2023-25047 on NVD →

RSVPMaker <= 9.9.3 - Authenticated (Admin+) SQL Injection via $email value

high

The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the ‘$email’ variable in versions up to, and including, 9.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Admin level attackers to append additi...

CVSS:
7.2
Affected:
up to 9.9.3
Fixed in:
9.9.4
Disclosed:
Feb 13, 2023

CVE-2023-25045 on NVD →

RSVPMaker [rsvpmaker] < 9.3.3

unknown

[en] The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the da...

Affected:
up to 9.3.3
Fixed in:
9.3.3
Disclosed:
Jun 13, 2022

CVE-2022-1768 on NVD →

RSVPMaker <= 9.3.2 - Unauthenticated SQL Injection

critical

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the databas...

CVSS:
9.8
Affected:
up to 9.3.2
Fixed in:
9.3.3
Disclosed:
May 17, 2022

CVE-2022-1768 on NVD →

RSVPMaker [rsvpmaker] < 9.2.7

unknown

[en] The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the databa...

Affected:
up to 9.2.7
Fixed in:
9.2.7
Disclosed:
May 10, 2022

CVE-2022-1505 on NVD →

RSVPMaker [rsvpmaker] < 9.2.6

unknown

[en] The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in ver...

Affected:
up to 9.2.6
Fixed in:
9.2.6
Disclosed:
May 10, 2022

CVE-2022-1453 on NVD →

RSVPMaker <= 9.2.6 - Unauthenticated SQL Injection

critical

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in...

CVSS:
9.8
Affected:
up to 9.2.6
Fixed in:
9.2.7
Disclosed:
Apr 27, 2022

CVE-2022-1505 on NVD →

RSVPMaker <= 9.2.5 - Unauthenticated SQL Injection

critical

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions...

CVSS:
9.8
Affected:
up to 9.2.5
Fixed in:
9.2.6
Disclosed:
Apr 26, 2022

CVE-2022-1453 on NVD →

RSVPMaker [rsvpmaker] < 8.7.4

unknown

[en] The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF at...

Affected:
up to 8.7.4
Fixed in:
8.7.4
Disclosed:
Aug 2, 2021

CVE-2021-24371 on NVD →

RSVPMaker <= 8.7.2 - Server-Side Request Forgery

low

The Import feature of the RSVPMaker WordPress plugin before 8.7.4 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack.

CVSS:
2.7
Affected:
up to 8.7.3
Fixed in:
8.7.4
Disclosed:
Jun 29, 2021

CVE-2021-24371 on NVD →

RSVPMaker <= 7.8.1 - Unauthenticated SQL Injection via 'event_count'

critical

The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'event_count' parameter called via the 'signed_up' AJAX in versions up to, and including, 7.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
9.8
Affected:
up to 7.8.2
Fixed in:
7.8.2
Disclosed:
Aug 22, 2020

RSVPMaker [rsvpmaker] < 7.8.2

unknown

The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'event_count' parameter called via the 'signed_up' AJAX in versions up to, and including, 7.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

Affected:
up to 7.8.2
Fixed in:
7.8.2
Disclosed:
Aug 22, 2020

RSVPMaker [rsvpmaker] < 7.8.2

unknown

Unauthenticated SQL Injection (SQLi) vulnerability found by CBiu in WordPress RSVPMaker plugin (versions <= 7.8.1).

Affected:
up to 7.8.2
Fixed in:
7.8.2
Disclosed:
Aug 22, 2020

RSVPMaker [rsvpmaker] < 6.2

unknown

[en] The rsvpmaker plugin before 6.2 for WordPress has SQL injection.

Affected:
up to 6.2
Fixed in:
6.2
Disclosed:
Aug 27, 2019

CVE-2019-15646 on NVD →

RSVPMaker [rsvpmaker] < 5.6.4

unknown

[en] The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.

Affected:
up to 5.6.4
Fixed in:
5.6.4
Disclosed:
Aug 27, 2019

CVE-2018-21004 on NVD →

RSVPMaker <= 6.1.9 - SQL Injection

critical

The RSVPMaker plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 6.1.9 due to insufficient escaping on a user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
9.8
Affected:
up to 6.1.9
Fixed in:
6.2
Disclosed:
Apr 28, 2019

CVE-2019-15646 on NVD →

RSVPMaker [rsvpmaker] < 6.2.1

unknown

SQL Injection (SQLi) vulnerability found in WordPress RSVPMaker plugin (versions <= 6.1.9).

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Apr 28, 2019

RSVPMaker < 5.6.4 - SQL Injection

critical

The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.

CVSS:
9.8
Affected:
up to 5.6.4
Fixed in:
5.6.4
Disclosed:
Nov 8, 2018

CVE-2018-21004 on NVD →

RSVPMaker [rsvpmaker] < 2.5.5

unknown

WordPress RSVPMaker plugin is prone to a persistent XSS vulnerability. The RSVP form does not properly sanitize input fields. This vulnerability will fire when the admin views the event's attendance list in the RSVP report section. Update the plugin.

Affected:
up to 2.5.5
Fixed in:
2.5.5
Disclosed:
Aug 13, 2012

RSVPMaker [rsvpmaker] < 7.8.6

unknown

The plugin does not sanitise user input before using it in a SQL statement in the signed_up_ajax() AJAX action. Note: Even though the reported SQL Injection was fixed in v7.8.2, other additional sanitisation was implemented in v7.8.3 to 7.8.6.

Affected:
up to 7.8.6
Fixed in:
7.8.6

RSVPMaker [rsvpmaker] < 2.5.5

unknown

The RSVPMaker WordPress plugin was affected by an index.php RSVP Form Multiple Field XSS security vulnerability.

Affected:
up to 2.5.5
Fixed in:
2.5.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database