漏洞描述
WordPress RSVPMaker plugin through 9.3.2 contains a SQL injection vulnerability due to insufficient escaping and parameterization on user-supplied data passed to multiple SQL queries in ~/rsvpmaker-email.php. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
gist.github.comhttps://gist.github.com/Xib3rR4dAr/441d6bb4a5b8ad4b25074a49210a02cc↗wordpress.orghttps://wordpress.org/plugins/rsvpmaker/↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2725322%40rsvpmaker&new=2725322%40rsvpmaker&sfp_email=&sfph_mail=↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-1768↗www.wordfence.comhttps://www.wordfence.com/vulnerability-advisories/#CVE-2022-1768↗