CVE-2024-1123: EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the savefrontendeventsubmission() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary posts. This can also be exploited by unauthenticated attackers when the allowsubmissionbyanonymoususer setting is enabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1123?
CVE-2024-1123 has been classified as a medium severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-1123?
To fix CVE-2024-1123, update the EventPrime plugin to version 3.4.3 or later, which includes the necessary capability checks.
What systems are affected by CVE-2024-1123?
CVE-2024-1123 affects all versions of the EventPrime plugin for WordPress up to and including version 3.4.2.
Can CVE-2024-1123 be exploited by unauthenticated users?
CVE-2024-1123 requires authentication to exploit, but it can allow authenticated users to modify event submissions without proper permissions.
When was CVE-2024-1123 discovered?
CVE-2024-1123 was disclosed in early 2024 in relation to a vulnerability in the EventPrime plugin.