Vulnerability Description
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Liquidweb | Event Tickets | < 5.9.1 |
References
- https://wpscan.com/vulnerability/5904dc7e-1058-4c40-bca3-66ba57b1414b/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/5904dc7e-1058-4c40-bca3-66ba57b1414b/ExploitThird Party Advisory
FAQ
What is CVE-2024-1319?
CVE-2024-1319 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, priv...
How severe is CVE-2024-1319?
CVE-2024-1319 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1319?
Check the references section above for vendor advisories and patch information. Affected products include: Liquidweb Event Tickets.