Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown

CVE-2024-12024

Disclosure Date: December 17, 2024 (last updated January 13, 2025)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page. Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default.
Attacker Value
Unknown

CVE-2024-43223

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.
0
Attacker Value
Unknown

CVE-2024-9865

Disclosure Date: October 24, 2024 (last updated January 16, 2025)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the transaction log for a booking.
Attacker Value
Unknown

CVE-2024-9864

Disclosure Date: October 24, 2024 (last updated January 16, 2025)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when front-end users can submit new events with tickets.
Attacker Value
Unknown

CVE-2024-47648

Disclosure Date: October 10, 2024 (last updated November 14, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5.
Attacker Value
Unknown

CVE-2024-8369

Disclosure Date: September 10, 2024 (last updated September 27, 2024)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-protected events.
Attacker Value
Unknown

CVE-2024-31275

Disclosure Date: June 09, 2024 (last updated June 13, 2024)
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
Attacker Value
Unknown

CVE-2023-33321

Disclosure Date: May 17, 2024 (last updated February 04, 2025)
Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.
Attacker Value
Unknown

CVE-2024-29776

Disclosure Date: March 27, 2024 (last updated December 21, 2024)
Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
0
Attacker Value
Unknown

CVE-2024-24832

Disclosure Date: March 23, 2024 (last updated February 05, 2025)
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.