'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-03-18 | |
| Rule Name: | RSVP and Event Management Plugin Unauthenticated Access Vulnerability (CVE-2022-1054) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events. | |
| Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://wpscan.com/vulnerability/95a5fad1-e823-4571-8640-19bf5436578d |
|
| Solutions |
|---|
| Refer to the announcement or patch by the vendor. |