WordPress RSVP and Event Management Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the RSVP and Event Management plugin for WordPress, in all versions through 2.7.13. The issue arises from several AJAX functions lacking proper capability checks, which allows unauthorized access. This flaw enables unauthenticated attackers to delete questions and attendees, while authenticated users can modify question menu orders.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of questions and attendees, and unauthorized modification of question menu orders.

Reproduction

The vulnerability can be reproduced by sending a request to the WordPress site with the 'rsvp-bulk-action' parameter set to 'delete', along with the IDs of the attendees or questions to be deleted. This can be done without proper authorization, bypassing the intended capability checks.

Remediation

Users are advised to update the RSVP and Event Management plugin to version 2.7.14 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
8.6
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.