Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown
CVE-2024-12024
Disclosure Date: December 17, 2024 (last updated January 13, 2025)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.
Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default.
0
Attacker Value
Unknown
CVE-2024-43223
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.
0
Attacker Value
Unknown
CVE-2024-9865
Disclosure Date: October 24, 2024 (last updated January 16, 2025)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the transaction log for a booking.
0
Attacker Value
Unknown
CVE-2024-9864
Disclosure Date: October 24, 2024 (last updated January 16, 2025)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when front-end users can submit new events with tickets.
0
Attacker Value
Unknown
CVE-2024-47648
Disclosure Date: October 10, 2024 (last updated November 14, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5.
0
Attacker Value
Unknown
CVE-2024-8369
Disclosure Date: September 10, 2024 (last updated September 27, 2024)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-protected events.
0
Attacker Value
Unknown
CVE-2024-31275
Disclosure Date: June 09, 2024 (last updated June 13, 2024)
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
0
Attacker Value
Unknown
CVE-2023-33321
Disclosure Date: May 17, 2024 (last updated February 04, 2025)
Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.
0
Attacker Value
Unknown
CVE-2024-29776
Disclosure Date: March 27, 2024 (last updated December 21, 2024)
Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
0
Attacker Value
Unknown
CVE-2024-24832
Disclosure Date: March 23, 2024 (last updated February 05, 2025)
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
0