vendor:
Event Registration
by:
k3m4n9i
6,8
CVSS
SQL Injection
89
CWE
Product Name: Event Registration
Affected Version From: 5.32
Affected Version To: 5.32
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2010
WordPress Event Registration SQL injection
An attacker can exploit a SQL injection vulnerability in the Event Registration plugin for WordPress. By sending a specially crafted request to the vulnerable server, an attacker can execute arbitrary SQL commands in the back-end database. This can be used to bypass authentication and gain access to sensitive data such as passwords, usernames, and other sensitive information stored in the database.
Mitigation:
Upgrade to the latest version of the plugin.