MEDIUM
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export
Published Mar 13, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.53%
Description
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_all() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all event booking which can contain PII.
Affected products
-
- Version 0StatusaffectedConstraints<=3.4.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Metagauss | EventPrime – Events Calendar, Bookings and Tickets | unaffected |
|
- < 3.4.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16901 Advisory
- https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/trunk//includes/service/class-ep-ajax.php#L1994 Not Applicable
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3033882%40eventprime-event-calendar-management&new=3033882%40eventprime-event-calendar-management&sfp_email=&sfph_mail= Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/39da62be-e630-48cd-b732-80ed3d337638?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Mar 13, 2024
Updated Apr 8, 2026
Reserved Jan 31, 2024
Link CVE-2024-1127
CISA Vulnrichment
Updated Mar 13, 2024
ENISA EUVD
EUVD-2024-16901 Assigner Wordfence
Published Mar 13, 2024
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2024-16901