RSVP and Event Management
RSVP and Event Management has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; all 7 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 6.1 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 3 of the records (43%). Other recurring categories include Cross-Site Scripting, Exposure Of Sensitive Information To An Unauthorized Actor.
Every one of the 7 issues recorded for RSVP and Event Management has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, one record each. RSVP and Event Management is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
RSVP and Event Management <= 2.7.4 - Cross-Site Scripting
Read the full analysisVulnerability Records

RSVP and Event Management
Author
WP Chill
Simple Event Registration & RSVP Management for WordPress The RSVP Plugin helps you handle event sign-ups easily. It lets people say if they are coming to your event. There are two versions: Free and Pro. The Free version has basic tools to manage one event. The Pro version gives you extra features for bigger and more detailed events. Here are the premium features available in the paid version of RSVP Manage multiple events Setup sub-events, for example if you have an event spanning multiple days and you wish to create a separate event on each day Provide a calendar invite for events Create reminder emails for your attendees Generate QR Codes Record event attendance with a check-in functionality Display attendees list in the front-end Setup a Waiting list for your events Receive priority support
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C