peter bassill · operator
$ cve CVE-2022-1768 JSON

CVE-2022-1768

9.8
CRITICAL · CVSS 3.1 · EPSS 12.9% (pctl 96)

Patch early

EPSS 12.9% — above the 10% action threshold.

Description

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.86% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2022-06-13
Last modified2026-06-17

Affected (1)

VendorProduct
carrcommunicationsrsvpmaker

References

→ the Explorer  ·  watch your stack  ·  NVD