PT-2024-16868 · WordPress · Eventprime – Events Calendar

Lucio Sá

·

Published

2024-03-13

·

Updated

2025-01-15

·

CVE-2024-1126

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress versions up to, and including, 3.4.1
Description The issue is related to unauthorized access of data due to a missing capability check on the get attendees email by event id() function. This allows authenticated attackers with subscriber-level access and above to retrieve the attendees list for any event.
Recommendations For versions up to, and including, 3.4.1, consider disabling the get attendees email by event id() function until a patch is available to prevent unauthorized access to attendee data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1126

Affected Products

Eventprime – Events Calendar