S4E just found a low dns any record query
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1054 Scanner

Detects 'Improper Access Control' vulnerability in RSVP and Event Management plugin for WordPress affects v. before 2.7.8.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1054
5.3
CVSS

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
RSVP and Event Management Plugin
AFFECTED< 2.7.2*SAFE ✓≥ 2.7.2*
Updated Aug 19, 2026View on NVD →
Detail

The RSVP and Event Management plugin for WordPress is a popular plugin used by website administrators to organize and manage events, registrations, and RSVPs for different activities. This plugin simplifies the process of managing events, as it allows the user to customize event pages, send reminders, and track attendance. It is popular for use in various settings, including business conferences, webinars, networking events, and church functions.

Recently, a vulnerability was detected in the plugin, identified as CVE-2022-1054. This vulnerability affects versions prior to 2.7.8 of the plugin. The issue arises because the export function is hooked to the init action, which means that unauthenticated attackers can misuse the plugin to extract personally identifiable information (PII) such as users' first names, last names, and emails. In other words, the vulnerability can lead to the compromise of the personal data of event attendees.

If exploited, this vulnerability can lead to severe consequences for both website administrators and users. Cybercriminals can use the stolen PII to perform further attacks against individuals and organizations. For example, attackers could sell the stolen data on the black market to identity thieves, causing financial and reputational damage. Users may also face phishing and social engineering attacks as a result of the data breach. Moreover, the event organizers may face legal consequences for not complying with data protection regulations.

s4e.io offers pro features that enable users to track and identify vulnerabilities in their digital assets quickly and efficiently. Thanks to their comprehensive scanning abilities and easy-to-use interface, website administrators can evaluate their website's security and quickly resolve any issues that may arise. Therefore, we highly recommend using the pro features of s4e.io for a secure digital experience.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website administrators can take the following precautions:

  • Update the plugin to the latest version (2.7.8) that fixes this issue.
  • Remove the plugin if it is no longer in use.
  • Implement access controls on the export function to limit access to authorized personnel only.
  • Use data encryption methods to protect personal data stored on the website.
  • Monitor the website regularly for any signs of suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.