First published: Mon Nov 27 2023(Updated: )
The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Eventprime | <=3.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4252 is a vulnerability in the EventPrime WordPress Plugin that allows an attacker to bypass the booking pricing and purchase bookings without payment.
The severity of CVE-2023-4252 is medium with a CVSS score of 5.3.
CVE-2023-4252 affects EventPrime version up to 3.2.9.
An attacker can exploit CVE-2023-4252 by specifying the price of a booking in the client request and purchasing bookings without payment.
Yes, updating EventPrime to version 3.2.10 or later will fix CVE-2023-4252.