Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Caon

#21573of 53,622
11.1Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-21476
6.4
2025-05-15
WordPress · Eventprime · CVE-2024-4665
Name of the Vulnerable Software and Affected Versions: EventPrime WordPress plugin versions prior to 3.5.0 Description: The issue concerns a lack of proper permission validation when updating bookings, allowing users to change or cancel bookings for other users. Additionally, the feature lacks a nonce, which is a security token used to prevent cross-site request forgery (CSRF) attacks. Recommendations: For versions prior to 3.5.0, update to version 3.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the booking update feature to minimize the risk of exploitation.
PT-2024-35451
4.7
2024-07-13
Unknown · Wp-Affiliate-Platform · CVE-2024-5280
**Name of the Vulnerable Software and Affected Versions** wp-affiliate-platform versions prior to 6.5.1 **Description** The issue concerns a lack of CSRF check and missing sanitization as well as escaping in certain areas, potentially allowing attackers to execute an XSS payload via a CSRF attack on non-logged-in users. **Recommendations** For versions prior to 6.5.1, update to version 6.5.1 or later to resolve the issue.