CVE-2024-12711
RSVP and Event Management <= 2.7.13 - Missing Authorization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questions and attendees and for authenticated users to update question menu orders.
El complemento RSVP y Event Management para WordPress es vulnerable al acceso no autorizado debido a una verificación de capacidad faltante en varias funciones AJAX como bulk_delete_attendees() y bulk_delete_questions() en todas las versiones hasta la 2.7.13 incluida. Esto permite que atacantes no autenticados eliminen preguntas y asistentes y que usuarios autenticados actualicen los pedidos del menú de preguntas.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-12-17 CVE Reserved
- 2025-01-06 CVE Published
- 2025-01-07 CVE Updated
- 2025-01-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpchill Search vendor "Wpchill" | RSVP And Event Management Search vendor "Wpchill" for product "RSVP And Event Management" | <= 2.7.13 Search vendor "Wpchill" for product "RSVP And Event Management" and version " <= 2.7.13" | en |
Affected
|