First published: Sat Mar 09 2024(Updated: )
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary posts. This can also be exploited by unauthenticated attackers when the allow_submission_by_anonymous_user setting is enabled.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss EventPrime | <3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1123 has been classified as a medium severity vulnerability due to its potential for unauthorized data modification.
To fix CVE-2024-1123, update the EventPrime plugin to version 3.4.3 or later, which includes the necessary capability checks.
CVE-2024-1123 affects all versions of the EventPrime plugin for WordPress up to and including version 3.4.2.
CVE-2024-1123 requires authentication to exploit, but it can allow authenticated users to modify event submissions without proper permissions.
CVE-2024-1123 was disclosed in early 2024 in relation to a vulnerability in the EventPrime plugin.