First published: Wed Mar 13 2024(Updated: )
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_email_by_event_id() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to to retrieve the attendees list for any event.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss EventPrime | <3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-1126 is classified as medium due to the unauthorized access it allows to sensitive attendee data.
To fix CVE-2024-1126, update the EventPrime plugin for WordPress to version 3.4.2 or later.
Authenticated users of the EventPrime plugin for WordPress versions up to and including 3.4.1 are impacted by CVE-2024-1126.
CVE-2024-1126 affects the EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress.
CVE-2024-1126 exposes attendee email addresses associated with events due to a lack of proper capability checks.