CVE-2023-29095
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Jul 10, 2023
Updated: Sep 30, 2023
CWE ID 89
Summary
CVE-2023-29095 is a critical SQL Injection vulnerability affecting versions 10.5.5 and below of the David F. Carr RSVPMaker plugin for WordPress. An attacker can exploit this Admin-level authentication vulnerability by injecting malicious SQL queries, potentially gaining unauthorized access to sensitive data or taking control of the affected system. This issue poses a significant risk to WordPress websites utilizing the RSVPMaker plugin and urgent action is required to update to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Carrcommunications