CVE-2024-12711: Wpchill Rsvp And Event Management
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questions and attendees and for authenticated users to update question menu orders.
Affected products
- Wpchill Rsvp And Event Management: up to and including 2.7.13
Published 2025-01-07. Last modified 2026-06-17.