CVE-2024-1321: EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events for free.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1321?
CVE-2024-1321 is classified as a high severity vulnerability due to its potential to allow unauthorized payment bypass.
How do I fix CVE-2024-1321?
To fix CVE-2024-1321, update the EventPrime plugin to version 3.4.3 or newer.
Who is affected by CVE-2024-1321?
All users of the EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress versions up to and including 3.4.2 are affected by CVE-2024-1321.
What type of vulnerability is CVE-2024-1321?
CVE-2024-1321 is a payment bypass vulnerability that allows unauthenticated users to update order payment statuses.
Can CVE-2024-1321 be exploited remotely?
Yes, CVE-2024-1321 can be exploited remotely since it allows unauthenticated users to manipulate payment statuses.