CVE-2022-1453

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
10/05/2022
Last modified:
08/04/2026

Description

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:carrcommunications:rsvpmaker:*:*:*:*:*:wordpress:*:* 9.2.6 (excluding)