Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16.
History

Mon, 13 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpchill
Wpchill rsvp And Event Management
Vendors & Products Wordpress
Wordpress wordpress
Wpchill
Wpchill rsvp And Event Management

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16.
Title WordPress RSVP and Event Management plugin <= 2.7.16 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-13T15:27:59.658Z

Reserved: 2026-04-07T10:48:15.448Z

Link: CVE-2026-39536

cve-icon Vulnrichment

Updated: 2026-04-13T15:27:44.717Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:26.360

Modified: 2026-04-13T16:16:30.467

Link: CVE-2026-39536

cve-icon Redhat

No data.