CVE-2024-13526: EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the exportsubmittionattendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download list of attendees for any event.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13526?
CVE-2024-13526 is rated as a high severity vulnerability due to the risk of unauthorized access to sensitive data.
How do I fix CVE-2024-13526?
To fix CVE-2024-13526, update the EventPrime Events Calendar, Bookings and Tickets plugin to version 4.0.7.4 or later.
What kind of data is exposed by CVE-2024-13526?
CVE-2024-13526 allows unauthorized access to attendee data submitted through the events management system.
Which versions of the EventPrime plugin are affected by CVE-2024-13526?
CVE-2024-13526 affects all versions of the EventPrime Events Calendar, Bookings and Tickets plugin up to and including version 4.0.7.3.
Is user authentication sufficient to protect against CVE-2024-13526?
No, user authentication is not sufficient because the vulnerability allows unauthorized data export despite being logged in.