PT-2024-17941 · WordPress · Eventprime – Events Calendar

Lucio Sá

·

Published

2024-03-13

·

Updated

2025-01-15

·

CVE-2024-1321

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress versions up to, and including, 3.4.2
Description The issue allows unauthenticated users to update the status of order payments, making it possible for attackers to book events for free. This is due to the plugin permitting unauthenticated access to modify payment statuses.
Recommendations For versions up to, and including, 3.4.2, update to a version later than 3.4.2 to resolve the issue. As a temporary workaround, consider restricting access to the payment status update functionality to authenticated users only.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2024-1321

Affected Products

Eventprime – Events Calendar