CVE-2024-6883: Event Espresso 4 Decaf – Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification
The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability check on the saveTimezoneString and some other functions in all versions up to and including 4.10.46.decaf. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify some of the plugin settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6883?
CVE-2024-6883 has been rated as a medium severity vulnerability due to unauthorized access to plugin settings.
How do I fix CVE-2024-6883?
To fix CVE-2024-6883, update the Event Espresso 4 Decaf plugin to the latest version that addresses this vulnerability.
What versions are affected by CVE-2024-6883?
CVE-2024-6883 affects all versions of Event Espresso 4 Decaf up to and including 5.0.22.decaf.
Who is impacted by CVE-2024-6883?
Users of the Event Espresso 4 Decaf plugin in WordPress are impacted by CVE-2024-6883 due to the lack of capability checks.
What types of attacks can exploit CVE-2024-6883?
CVE-2024-6883 can be exploited to modify plugin settings without proper authorization.