WordPress Plugin Vulnerabilities

EventPrime < 3.3.6 - Unauthenticated Event Access

Description

The plugin lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Miguel Santareno
Submitter
Miguel Santareno
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2023-12-29 (about 1 year ago)
Added
2023-12-29 (about 1 year ago)
Last Updated
2023-12-29 (about 1 year ago)

Other