CVE-2024-1126: EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Attendee List Retrieval
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getattendeesemailbyeventid() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to to retrieve the attendees list for any event.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1126?
The severity of CVE-2024-1126 is classified as medium due to the unauthorized access it allows to sensitive attendee data.
How do I fix CVE-2024-1126?
To fix CVE-2024-1126, update the EventPrime plugin for WordPress to version 3.4.2 or later.
Who is impacted by CVE-2024-1126?
Authenticated users of the EventPrime plugin for WordPress versions up to and including 3.4.1 are impacted by CVE-2024-1126.
What is affected by CVE-2024-1126?
CVE-2024-1126 affects the EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress.
What data is exposed in CVE-2024-1126?
CVE-2024-1126 exposes attendee email addresses associated with events due to a lack of proper capability checks.