PT-2021-16379 · WordPress · Events Calendar

Krzysztof Zając

·

Published

2021-12-06

·

Updated

2021-12-07

·

CVE-2021-24943

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Registrations for the Events Calendar WordPress plugin versions prior to 2.7.6
Description: The issue arises from the lack of sanitization and escaping of the event id in the /wp-admin/admin-ajax.php 'rtec send unregister link' AJAX action, which is accessible to both unauthenticated and authenticated users. This oversight leads to an unauthenticated SQL injection.
Recommendations: For versions prior to 2.7.6, update to version 2.7.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'rtec send unregister link' AJAX action until a patch is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24943

Affected Products

Events Calendar