CVE-2024-11133: Eventer <= 3.9.9.5 - Missing Authorization to Unauthenticated Event Ticket Download
Published Feb 3, 2025
·Updated
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handlepdfdownloadrequest' function in all versions up to, and including, 3.9.9.5. This makes it possible for unauthenticated attackers to download event tickets.
Affected Software
1 affected component
imithemes Eventer Wordpress<=3.9.9
Event History
Feb 3, 2025
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-11133?
CVE-2024-11133 is considered a critical vulnerability due to its potential for unauthenticated data access.
2
How do I fix CVE-2024-11133?
To fix CVE-2024-11133, upgrade the Eventer plugin to version 3.10 or later.
3
Who is affected by CVE-2024-11133?
All users of the Eventer plugin for WordPress versions up to 3.9.9 are affected by CVE-2024-11133.
4
What type of attack does CVE-2024-11133 allow?
CVE-2024-11133 allows unauthorized attackers to download event tickets without authentication.
5
Is there a patch for CVE-2024-11133?
Yes, a patch is included in versions of the Eventer plugin released after 3.9.9.