CVE-2021-24943: Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the eventid in the rtecsendunregisterlink AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24943?
CVE-2021-24943 has been classified as a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2021-24943?
To fix CVE-2021-24943, update the Registrations for the Events Calendar plugin to version 2.7.6 or later.
What type of vulnerability is CVE-2021-24943?
CVE-2021-24943 is a SQL injection vulnerability that affects the Registrations for the Events Calendar plugin.
Can CVE-2021-24943 be exploited by unauthenticated users?
Yes, CVE-2021-24943 can be exploited by both unauthenticated and authenticated users.
Which versions of the plugin are affected by CVE-2021-24943?
CVE-2021-24943 affects versions of the Registrations for the Events Calendar plugin before 2.7.6.