Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51066 | The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questions and attendees and for authenticated users to update question menu orders. |
Tue, 07 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Jan 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questions and attendees and for authenticated users to update question menu orders. | |
| Title | RSVP and Event Management <= 2.7.13 - Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:25:19.678Z
Reserved: 2024-12-17T16:10:12.704Z
Link: CVE-2024-12711
Updated: 2025-01-07T14:20:22.586Z
Status : Deferred
Published: 2025-01-07T12:15:24.503
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-12711
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:14Z
EUVD