{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/micahblu/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:micahblu:rsvp_me:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2024-50491"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rsvp Me (\u003c= 1.9.9)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","wordpress","cve-2024-50491"],"_cs_type":"advisory","_cs_vendors":["Micahblu"],"content_html":"\u003cp\u003eThe Micahblu Rsvp Me WordPress plugin is vulnerable to an unauthenticated SQL injection flaw, identified as CVE-2024-50491. The vulnerability exists in all versions up to and including 1.9.9. It stems from insufficient sanitization of the 'id' parameter when processed by the 'rsvp_me_event_data' action within the plugin. Because the input is not correctly handled or prepared, an attacker can inject malicious SQL commands into existing queries. This vulnerability allows unauthenticated remote actors to gain unauthorized access to the underlying MySQL database, facilitating the extraction of sensitive information. A public proof-of-concept exploit exists, which significantly lowers the barrier for exploitation by unauthorized parties.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing WordPress instance running the vulnerable Micahblu Rsvp Me plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the /wp-admin/admin-ajax.php endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker sets the 'action' parameter to 'rsvp_me_event_data'.\u003c/li\u003e\n\u003cli\u003eAttacker inserts malicious SQL payloads into the 'id' parameter, such as boolean-based or time-based blind injection queries.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to sanitize the input, passing the malicious payload directly to the back-end MySQL database.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected query, returning sensitive results or confirming the success of the blind injection.\u003c/li\u003e\n\u003cli\u003eAttacker iterates through the injection points to extract data from the database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to read data from the WordPress database, potentially leading to the compromise of sensitive user information, administrative credentials, or configuration details. Given the high CVSS score, organizations using this plugin are at high risk of data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Micahblu Rsvp Me plugin to a version beyond 1.9.9 immediately or disable the plugin if no patch is available.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to monitor or block HTTP requests to /wp-admin/admin-ajax.php containing SQL-related characters (e.g., 'SELECT', 'SLEEP', 'UNION', '--') in the 'id' parameter when 'action=rsvp_me_event_data'.\u003c/li\u003e\n\u003cli\u003eReview web access logs for anomalous POST requests to the admin-ajax.php endpoint that include SQL syntax patterns.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T12:42:25Z","date_published":"2026-09-02T12:42:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-50491/","summary":"An unauthenticated SQL injection vulnerability in the Micahblu Rsvp Me plugin for WordPress (\u003c= 1.9.9) allows remote attackers to extract sensitive database information via the 'id' parameter.","title":"Unauthenticated SQL Injection in Micahblu Rsvp Me WordPress Plugin (CVE-2024-50491)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-50491/"}],"language":"en","title":"CraftedSignal Threat Feed - Micahblu","version":"https://jsonfeed.org/version/1.1"}