CVE-2024-8369: EventPrime <= 4.0.4.3 - Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-protected events.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8369?
CVE-2024-8369 is classified as a critical vulnerability due to its potential for unauthorized access to private or password-protected events.
How do I fix CVE-2024-8369?
To fix CVE-2024-8369, update the EventPrime plugin to version 4.0.4.4 or later which addresses the missing authorization checks.
Who is affected by CVE-2024-8369?
CVE-2024-8369 affects all versions of the EventPrime plugin for WordPress up to and including 4.0.4.3.
What kind of attacks can occur due to CVE-2024-8369?
CVE-2024-8369 allows unauthorized users to access private or password-protected events, potentially leading to data exposure.
Is there a workaround for CVE-2024-8369?
There are no official workarounds for CVE-2024-8369, so upgrading to the fixed version is the recommended approach.