CVE-2021-24943
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
- Affected products
- Events Calendar
- Roundupwp Registrations For The Events Calendar
- < 2.7.6
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 7.5% (94th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-12-06
CVE-2021-24943 at NVD
1 known exploit for CVE-2021-24943
Proof-of-concept code and exploit modules indexed by Sploitus