Executive brief
The Registrations For The Events Calendar plugin for WordPress, which manages event sign-ups, contains a security flaw that allows certain authorized users to perform unauthorized database queries. An attacker with at least Contributor-level access could exploit this to extract sensitive information from the website's database. This could lead to the exposure of private user data or configuration details, potentially compromising the entire site.
Technical details
The vulnerability is a SQL injection located in the RTEC_Db_Admin::update_entry() function of the Registrations For The Events Calendar plugin. The rtec_records_edit AJAX action decodes a JSON object from the 'standard' POST parameter and uses its keys as column identifiers in a SQL UPDATE statement. While the plugin applies esc_sql() to these keys, this function does not prevent the injection of spaces, parentheses, or hyphens, allowing an attacker to break out of the identifier context. Authenticated attackers with Contributor-level permissions or higher can leverage this to inject subqueries and extract sensitive data from the database. The issue is present in versions up to and including 3.2.
Affected products
- roundupwp Registrations For The Events Calendar up to and including 3.2
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory
References
- https://plugins.trac.wordpress.org/browser/registrations-for-the-events-calendar/tags/3.2/includes/admin/admin-functions.php
- https://plugins.trac.wordpress.org/browser/registrations-for-the-events-calendar/tags/3.2/includes/admin/admin-functions.php
- https://plugins.trac.wordpress.org/browser/registrations-for-the-events-calendar/tags/3.2/includes/admin/class-rtec-db-admin.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3599275%40registrations-for-the-events-calendar&new=3599275%40registrations-for-the-events-calendar
- https://www.wordfence.com/threat-intel/vulnerabilities/id/630cc68e-102e-4e05-98ff-94de434a10ae?source=cve