CVE-2024-6033: Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'importfile' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to import events, speakers, schedules and attendee data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Event Manager, Events Calendar, Tickets, Registrations – Eventinto a version that resolves this vulnerability.Fixed in 4.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6033?
CVE-2024-6033 has a medium severity due to its potential for unauthorized data importation.
How do I fix CVE-2024-6033?
To fix CVE-2024-6033, update the Eventin plugin to version 4.0.5 or later.
What systems are affected by CVE-2024-6033?
CVE-2024-6033 affects all versions of the Eventin plugin for WordPress up to and including 4.0.4.
What is the impact of CVE-2024-6033?
The impact of CVE-2024-6033 is that unauthorized users can import data improperly due to a missing capability check.
Is CVE-2024-6033 being actively exploited?
As of now, there is no specific indication that CVE-2024-6033 is being actively exploited.