PT-2025-1623 · WordPress · Eventer

István Márton

·

Published

2025-02-03

·

Updated

2025-02-03

·

CVE-2024-11134

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eventer plugin for WordPress versions prior to 3.9.10
Description The issue allows unauthorized access to data due to a missing capability check on the eventer export bookings csv function. This enables authenticated attackers with subscriber-level permissions or above to download bookings containing customers' personal data.
Recommendations For versions prior to 3.9.10, update to version 3.9.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the eventer export bookings csv function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-11134

Affected Products

Eventer