PoC Index

CVE-2022-1054

MEDIUM 5.3EPSS 4.2%

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
4.21% chance of exploitation in the next 30 days, 90th percentile
Nuclei
medium · CWE-862
Published
2022-04-18
Updated
2024-08-02

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related