WordPress Plugin Vulnerabilities

Registrations for the Events Calendar < 2.12.2 - Missing Authorization

Description

The Registrations for the Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtec_process_form_submission() and rtec_records_edit() functions in versions up to, and including, 2.12.1. This makes it possible for authenticated attackers, with contributor-level access and above, to edit and register for events they should not have access to.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Manab Jyoti Dowarah
Verified
No

Timeline

Publicly Published
2024-08-07 (about 2 years ago)
Added
2024-08-14 (about 2 years ago)
Last Updated
2024-08-14 (about 2 years ago)

Other