Access violation vulnerability in RSVP and Event Management 2.7.13

The plugin called RSVP and Event Management for WordPress has a security issue that allows people to access it without permission. This is because certain functions, such as bulk deleting attendees and questions, do not have proper checks in place. This means that anyone can delete questions and attendees without logging in, and users who are logged in can change the order of questions.

Detected in:

RSVP and Event Management fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.