CVE-2024-1316: Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Access
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1316?
CVE-2024-1316 has a medium severity rating as it allows unauthorized users to access event information they shouldn't see.
How do I fix CVE-2024-1316?
To fix CVE-2024-1316, update the Event Tickets and Registration plugin to version 5.8.1 or later and the Events Tickets Plus plugin to version 5.9.1 or later.
Who is affected by CVE-2024-1316?
CVE-2024-1316 affects users with the contributor role within the WordPress platform using outdated versions of specific Modern Tribe plugins.
What are the consequences of CVE-2024-1316?
The consequences of CVE-2024-1316 include potential unauthorized disclosure of event information such as drafts or private events.
Is CVE-2024-1316 exploit publicly available?
As of now, there are no known publicly available exploits for CVE-2024-1316, but it is advisable to apply updates promptly.