S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1768 Scanner

CVE-2022-1768 scanner - SQL Injection (SQLi) vulnerability in RSVPMaker plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1768
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
RSVPMakerby davidfcarr
0
Updated Aug 22, 2026View on NVD →
Detail

The RSVPMaker plugin for WordPress is a tool used for event planning and management, primarily for hosting events such as webinars, meetings, and seminars. This plugin allows users to create event pages, RSVP forms, and track attendance. It is a widely used plugin that has been downloaded over 20,000 times from the WordPress repository.

However, there is a new security risk associated with this plugin, known as CVE-2022-1768. This vulnerability arises due to insufficient sanitization and escaping of user inputs in the RSVPMaker-email.php file. As a result of this vulnerability, unauthenticated attackers can launch a SQL injection attack on the system, allowing them to extract sensitive information from the database.

The exploitation of this vulnerability can lead to significant damage to a website, especially for ones that store sensitive user data. Attackers can steal user credentials, payment information, and other confidential data, which can be sold on the black market or used for malicious purposes.

In conclusion, It is crucial to stay informed of vulnerabilities in your digital assets, including WordPress plugins and extensions. Thanks to the pro features offered by the s4e.io platform, you can quickly and effortlessly secure your website against any vulnerabilities. By staying updated and taking necessary security precautions, website owners can ensure that their digital assets remain protected from any malicious attacks.

 

REFERENCES

Solution Advice

To protect against CVE-2022-1768, website administrators can consider taking the following precautions:

  • Update the RSVPMaker plugin to the latest version (9.4.1 or above)
  • Remove unused or deprecated plugins, including RSVPMaker, from the website.
  • Implement a web application firewall to detect and block SQL injection attacks.
  • Block all unnecessary outgoing network traffic.
  • Regularly perform security audits on the website to detect and resolve vulnerabilities, including SQL injection attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-1768 scanner - SQL Injection (SQLi) vulnerability in RSVPMaker plugin for WordPress | S4E