← volver
CVE-2024-1316

Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Access

CVSS 6.5 MEDIUMEPSS 0.6%
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 mar 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N