![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-7982 – Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS
https://notcve.org/view.php?id=CVE-2024-7982
18 Oct 2024 — The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name parameters in all versions up to, and including, 2.12.3 due to insufficient input sanitization and output escapin... • https://wpscan.com/vulnerability/d79e1e9c-980d-4974-bfbd-d87d6e28d9a6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-43143 – WordPress Registrations for the Events Calendar plugin <= 2.12.1 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2024-43143
07 Aug 2024 — Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1. The Registrations for the Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtec_process_form_submission() and rtec_records_edit() functions in versions up to, and including, 2.12.1. This ma... • https://patchstack.com/database/vulnerability/registrations-for-the-events-calendar/wordpress-registrations-for-the-events-calendar-plugin-2-12-1-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-39638 – WordPress Registrations for the Events Calendar plugin <= 2.12.2 - SQL Injection vulnerability
https://notcve.org/view.php?id=CVE-2024-39638
30 Jul 2024 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2. The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.12.2 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara... • https://patchstack.com/database/vulnerability/registrations-for-the-events-calendar/wordpress-registrations-for-the-events-calendar-plugin-2-12-2-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-25083 – Registrations for the Events Calendar < 2.7.10 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25083
27 Dec 2021 — The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting El plugin Registrations for the Events Calendar de WordPress versiones anteriores a 2.7.10, no escapa el parámetro qtype antes de devolverlo en un atributo en la página de configuración, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://plugins.trac.wordpress.org/changeset/2648377 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-24943 – Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection
https://notcve.org/view.php?id=CVE-2021-24943
08 Nov 2021 — The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection. El plugin Registrations for the Events Calendar de WordPress versiones anteriores a 2.7.6, no sanea ni escapa del parámetro event_id en la acción AJAX rtec_send_unregister_link (disponible tanto para usuarios no ... • https://wpscan.com/vulnerability/ba50c590-42ee-4523-8aa0-87ac644b77ed • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-24876 – Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24876
27 Oct 2021 — The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting El plugin Registrations for the Events Calendar de WordPress versiones anteriores a 2.7.5, no escapa el parámetro v antes de devolverlo en un atributo, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/e77c2493-993d-418d-9629-a1f07b5a2b6f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •