CVE-2024-32110: WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.1.2 - Cross Site Request Forgery (CSRF) vulnerability
Published Jun 11, 2026
·Updated
Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery.
This issue affects WpEvently: from n/a through 4.1.2.
Affected Software
1 affected component
MagePeople WpEvently<=4.1.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Event Manager for WooCommerce (WpEvently / Magepeople)to a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Jun 11, 2026
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32110?
CVE-2024-32110 has a medium severity rating of 4.3.
2
How do I fix CVE-2024-32110?
To fix CVE-2024-32110, update the WordPress Event Manager for WooCommerce plugin to at least version 4.1.3.
3
What kind of vulnerability is CVE-2024-32110?
CVE-2024-32110 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of the WordPress Event Manager for WooCommerce plugin are affected by CVE-2024-32110?
CVE-2024-32110 affects versions of the plugin from n/a up to 4.1.2.
5
Who is the vendor for CVE-2024-32110?
The vendor for CVE-2024-32110 is MagePeople, specifically for their WpEvently plugin.