CVE-2025-24683: WordPress RSVP and Event Management Plugin <= 2.7.14 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill RSVP and Event Management rsvp allows SQL Injection.This issue affects RSVP and Event Management: from n/a through <= 2.7.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24683?
CVE-2025-24683 is classified as a high-severity SQL Injection vulnerability.
How do I fix CVE-2025-24683?
To fix CVE-2025-24683, upgrade the WPChill RSVP and Event Management Plugin to version 2.7.15 or later.
What versions are affected by CVE-2025-24683?
CVE-2025-24683 affects all versions of the WPChill RSVP and Event Management Plugin up to and including 2.7.14.
What type of vulnerability is CVE-2025-24683?
CVE-2025-24683 is an SQL Injection vulnerability resulting from improper neutralization of special elements in SQL commands.
Where can I find more information about CVE-2025-24683?
More detailed information about CVE-2025-24683 can be found in the vulnerability database entries associated with the WPChill RSVP and Event Management Plugin.