Junglewise Threat Intelligence

CVE-2026-39536: WP Chill RSVP and Event Management sensitive data exposure

CVE-2026-39536 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: WP Chill.

Executive brief

The RSVP and Event Management plugin for WordPress, which is used to manage event registrations and attendee lists, contains a security flaw that exposes sensitive system information. An unauthorized person could access data that is normally hidden, potentially revealing details about the website's configuration or user information. This exposure could be used by attackers to plan more sophisticated attacks against the site.

Technical details

The WP Chill RSVP and Event Management plugin for WordPress (versions <= 2.7.16) is vulnerable to CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere. This vulnerability allows an unauthenticated remote attacker to retrieve embedded sensitive data from the system. The flaw exists because the plugin does not properly restrict access to certain internal information or debug data within its control sphere. Attackers can exploit this over the network without any user interaction. A patch is available in version 2.7.17.

Affected products

  • WP Chill RSVP and Event Management <= 2.7.16

Timeline

  • 2026-02-10: other: Vulnerability reported by researcher
  • 2026-03-12: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: NVD publication date
  • 2026-04-08: patched: Patch available in version 2.7.17

References

Related threats