WPChill RSVP and Event Management
cpe:2.3:a:wpchill:rsvp_and_event_management:*:*:*:*:wordpress:*:*
- <= 2.7.13
A vulnerability exists in the RSVP and Event Management plugin for WordPress, in all versions through 2.7.13. The issue arises from several AJAX functions lacking proper capability checks, which allows unauthorized access. This flaw enables unauthenticated attackers to delete questions and attendees, while authenticated users can modify question menu orders.
Exploitation of this vulnerability allows for unauthorized deletion of questions and attendees, and unauthorized modification of question menu orders.
The vulnerability can be reproduced by sending a request to the WordPress site with the 'rsvp-bulk-action' parameter set to 'delete', along with the IDs of the attendees or questions to be deleted. This can be done without proper authorization, bypassing the intended capability checks.
Users are advised to update the RSVP and Event Management plugin to version 2.7.14 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.