Beschreibung
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the -standard- parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST[-standard-] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identifier; that function escapes quotes, backslashes, and a few control characters but does not escape spaces, equals signs, parentheses, or hyphens, so an attacker can break out of the identifier context and inject subqueries (terminated with a SQL comment). This makes it possible for authenticated attackers, with Contributor-level access and above who can edit the targeted event, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Veröffentlicht
- 2026-07-23 10:16:49
- Betroffene Versionen
- <=3.2
- Typ
- Webanwendung
- Zuletzt geändert
- 2026-07-23 15:14:51
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N