CVE-2023-29095

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jul 10, 2023
Updated: Sep 30, 2023
CWE ID 89

Summary

CVE-2023-29095 is a critical SQL Injection vulnerability affecting versions 10.5.5 and below of the David F. Carr RSVPMaker plugin for WordPress. An attacker can exploit this Admin-level authentication vulnerability by injecting malicious SQL queries, potentially gaining unauthorized access to sensitive data or taking control of the affected system. This issue poses a significant risk to WordPress websites utilizing the RSVPMaker plugin and urgent action is required to update to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share