Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 4.3epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Wired Impact Volunteer Managementpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/7541bc1a-a4ea-4e02-b10a-ea59708159f4/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.