Lucene search

K
wpvulndbWpvulndbWPVDB-ID:0B2A34B6-687A-4112-95E8-15BDE0F4DC33
HistoryFeb 06, 2024 - 12:00 a.m.

EventPrime < 3.4.0 - Improper Input Validation via save_event_booking

2024-02-0600:00:00
wpscan.com
9
wordpress
input validation
unauthorized modification
eventprime plugin
data security

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

Description The EventPrime plugin for WordPress is vulnerable to unauthorized modification of data due to improper input validation in the ‘save_event_booking’ function in versions up to, and including, 3.3.9. This makes it possible for unauthenticated attackers to modify the price and other attributes of purchased tickets.

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:0B2A34B6-687A-4112-95E8-15BDE0F4DC33