CVE-2024-1127: EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bookingexportall() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all event booking which can contain PII.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1127?
CVE-2024-1127 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive booking data.
How do I fix CVE-2024-1127?
To fix CVE-2024-1127, update the EventPrime plugin to version 3.4.2 or later, which includes the necessary capability checks.
Who is affected by CVE-2024-1127?
Users of the EventPrime plugin for WordPress, specifically those using versions up to and including 3.4.1, are affected by CVE-2024-1127.
What type of vulnerability is CVE-2024-1127?
CVE-2024-1127 is a vulnerability related to unauthorized access due to missing capability checks in the booking_export_all() function.
Can an unauthenticated attacker exploit CVE-2024-1127?
No, only authenticated users with certain privileges can exploit CVE-2024-1127 to access restricted data.