VYPR
Unrated severityNVD Advisory· Published Jul 10, 2023· Updated Apr 28, 2026

WordPress RSVPMarker Plugin < 10.5.5 is vulnerable to SQL Injection

CVE-2023-29095

Description

Admin+ SQL injection in RSVPMaker plugin versions below 10.5.5 allows database query injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Admin+ SQL injection in RSVPMaker plugin versions below 10.5.5 allows database query injection.

Vulnerability

An authenticated SQL injection vulnerability exists in the RSVPMaker plugin for WordPress, affecting all versions prior to 10.5.5. The flaw is present in the plugin's database query logic, requiring admin-level privileges to reach the vulnerable code path. [1]

Exploitation

An attacker must have an admin account (admin+) on the WordPress instance to exploit this vulnerability. No other prerequisites are mentioned in the available references. The attacker would then craft a malicious SQL payload within a plugin input field to inject unauthorized database commands. The exact injection vector and steps are not further detailed in the references. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary SQL queries on the underlying database. This can lead to disclosure of sensitive information, modification or deletion of data, and potentially privilege escalation within the WordPress application depending on the scope of the database account. [1]

Mitigation

Users should update the RSVPMaker plugin to version 10.5.5 or later, which contains the fix. No workarounds are documented, and the plugin does not appear on CISA's KEV list. [1]

References
  1. RSVPMaker

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.