WordPress Plugin Vulnerabilities

EventPrime < 3.3.6 - Booking Pricing Bypass

Description

The plugin specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Alex Sanford
Submitter
Alex Sanford
Submitter website
Verified
Yes

Timeline

Publicly Published
2023-10-30 (about 2 years ago)
Added
2023-10-31 (about 2 years ago)
Last Updated
2024-01-12 (about 1 year ago)

Other