CVE-2024-4665

Severity
6.4MEDIUM
EPSS
0.2%
top 62.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15

Description

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NExploitability: 3.1 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/eventprime3.4.93.5.0

🔴Vulnerability Details

2
CVEList
EventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update2025-05-15
GHSA
GHSA-6p5x-4w46-32gx: The EventPrime WordPress plugin before 32025-05-15
CVE-2024-4665 (MEDIUM CVSS 6.4) | The EventPrime WordPress plugin bef | cvebase.io