First published: Mon Dec 06 2021(Updated: )
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <2.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24943 has been classified as a high severity vulnerability due to its potential for SQL injection.
To fix CVE-2021-24943, update the Registrations for the Events Calendar plugin to version 2.7.6 or later.
CVE-2021-24943 is a SQL injection vulnerability that affects the Registrations for the Events Calendar plugin.
Yes, CVE-2021-24943 can be exploited by both unauthenticated and authenticated users.
CVE-2021-24943 affects versions of the Registrations for the Events Calendar plugin before 2.7.6.