WordPress Plugin Vulnerabilities

EventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update

Description

The plugin does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
caon
Submitter
caon
Submitter website
Verified
Yes

Timeline

Publicly Published
2024-04-23 (about 1 year ago)
Added
2024-10-29 (about 1 year ago)
Last Updated
2025-08-25 (about 5 months ago)

Other