CVE-2023-4252: EventPrime <= 3.2.9 - Booking Pricing Bypass
Published Nov 27, 2023
·Updated
The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
Affected Software
1 affected component
Metagauss Eventprime Wordpress<=3.2.9
Event History
Nov 27, 2023
CVE Published
04:21 PM
Data Sourced
04:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-4252?
CVE-2023-4252 is a vulnerability in the EventPrime WordPress Plugin that allows an attacker to bypass the booking pricing and purchase bookings without payment.
2
What is the severity of CVE-2023-4252?
The severity of CVE-2023-4252 is medium with a CVSS score of 5.3.
3
How does CVE-2023-4252 affect the EventPrime WordPress Plugin?
CVE-2023-4252 affects EventPrime version up to 3.2.9.
4
How can an attacker exploit CVE-2023-4252?
An attacker can exploit CVE-2023-4252 by specifying the price of a booking in the client request and purchasing bookings without payment.
5
Is there a fix for CVE-2023-4252?
Yes, updating EventPrime to version 3.2.10 or later will fix CVE-2023-4252.