PT-2025-10026 · WordPress · Eventprime – Events Calendar

Tim Coen

·

Published

2025-03-07

·

Updated

2025-08-12

·

CVE-2024-13526

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress versions up to, and including, 4.0.7.3
Description The issue allows authenticated attackers with Subscriber-level access and above to access data without proper authorization. This is due to missing capability checks on the export submittion attendees function, enabling them to download the list of attendees for any event.
Recommendations For versions up to, and including, 4.0.7.3, consider disabling the export submittion attendees function until a patch is available to prevent unauthorized access to event attendee lists.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-13526

Affected Products

Eventprime – Events Calendar