CRITICAL

CVE-2021-24943

CVSS v3

9.8

CRITICAL

EPSS Score

55.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

Technical details

Published
12/6/2021

Frequently asked questions

What is CVE-2021-24943?

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

Is CVE-2021-24943 actively exploited?

Active exploitation of CVE-2021-24943 has not been confirmed. The EPSS score is 55.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-24943?

CVE-2021-24943 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-24943 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.