cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-event-solution wp-event-solution

Direction: ascending
Jun 06, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin # CVE-2024-1122

CVE, Research URL

CVE-2024-1122

Date
Feb 09, 2024
Research Description
The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data.
Affected versions
max 3.3.51.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin # f4685f6f478a2942072b9c51ebe4f460c17ead60

Date
Dec 04, 2023
Research Description
Event Manager, Events Calendar, Tickets, Registrations &#8211; Eventin [wp-event-solution] < 3.3.53 WordPress Eventin Plugin <= 3.3.44 is vulnerable to Broken Access Control No patched version is available. Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Eventin Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.
Affected versions
max 3.3.53.
Status
vulnerable
Jun 10, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2023-49756

CVE, Research URL

CVE-2023-49756

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through <= 3.3.52.
Affected versions
max 3.3.53.
Status
vulnerable
Jul 08, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2024-37507

CVE, Research URL

CVE-2024-37507

Date
Jul 21, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.
Affected versions
max 4.0.0.
Status
vulnerable
Jul 18, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2024-6033

CVE, Research URL

CVE-2024-6033

Date
Jul 17, 2024
Research Description
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to import events, speakers, schedules and attendee data.
Affected versions
max 4.0.5.
Status
vulnerable
Aug 04, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2024-39648

CVE, Research URL

CVE-2024-39648

Date
Aug 02, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.
Affected versions
max 4.0.6.
Status
vulnerable
Sep 28, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2024-7149

CVE, Research URL

CVE-2024-7149

Date
Sep 27, 2024
Research Description
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected versions
max 4.0.9.
Status
vulnerable
Dec 23, 2024

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2024-56213

CVE, Research URL

CVE-2024-56213

Date
Dec 31, 2024
Research Description
Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7.
Affected versions
max 4.0.9.
Status
vulnerable
Feb 27, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-26964

CVE, Research URL

CVE-2025-26964

Date
Feb 25, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.20.
Affected versions
max 4.0.21.
Status
vulnerable
Mar 21, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-1766

CVE, Research URL

CVE-2025-1766

Date
Mar 20, 2025
Research Description
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to 'completed', possibly resulting in financial loss.
Affected versions
max 4.0.25.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-1770

CVE, Research URL

CVE-2025-1770

Date
Mar 20, 2025
Research Description
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected versions
max 4.0.25.
Status
vulnerable
Apr 18, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-39584

CVE, Research URL

CVE-2025-39584

Date
Apr 16, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.25.
Affected versions
max 4.0.26.
Status
vulnerable
May 09, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-3419

CVE, Research URL

CVE-2025-3419

Date
May 08, 2025
Research Description
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerability.
Affected versions
max 4.0.27.
Status
vulnerable
May 16, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-47445

CVE, Research URL

CVE-2025-47445

Date
May 14, 2025
Research Description
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.
Affected versions
max 4.0.27.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-47539

CVE, Research URL

CVE-2025-47539

Date
May 23, 2025
Research Description
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.
Affected versions
max 4.0.27.
Status
vulnerable
Jul 03, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-49321

CVE, Research URL

CVE-2025-49321

Date
Jun 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28.
Affected versions
max 4.0.29.
Status
vulnerable
Aug 09, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-4796

CVE, Research URL

CVE-2025-4796

Date
Aug 09, 2025
Research Description
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Affected versions
max 4.0.35.
Status
vulnerable
Aug 18, 2025

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-49869

CVE, Research URL

CVE-2025-49869

Date
Aug 14, 2025
Research Description
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.0.31.
Affected versions
max 4.0.32.
Status
vulnerable
Jan 28, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-68047

CVE, Research URL

CVE-2025-68047

Date
Jan 22, 2026
Research Description
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.
Affected versions
max 4.1.4.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-14657

CVE, Research URL

CVE-2025-14657

Date
Jan 09, 2026
Research Description
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to modify plugin settings. Furthermore, due to insufficient input sanitization and output escaping on the 'etn_primary_color' setting, this enables unauthenticated attackers to inject arbitrary web scripts that will execute whenever a user accesses a page where Eventin styles are loaded.
Affected versions
max 4.0.52.
Status
vulnerable
Apr 15, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-4109

CVE, Research URL

CVE-2026-4109

Date
Apr 14, 2026
Research Description
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order data including customer PII (name, email, phone) by iterating order IDs.
Affected versions
max 4.1.9.
Status
vulnerable
Apr 23, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2025-7813

CVE, Research URL

CVE-2025-7813

Date
Aug 23, 2025
Research Description
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected versions
max 4.0.38.
Status
vulnerable
May 06, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-40776

CVE, Research URL

CVE-2026-40776

Date
Jun 16, 2026
Research Description
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
Affected versions
max 4.1.9.
Status
vulnerable
Jul 11, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-12924

CVE, Research URL

CVE-2026-12924

Date
Jul 10, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 4.1.16.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13039

CVE, Research URL

CVE-2026-13039

Date
Jul 11, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is authorized to perform an action in the payment_complete() function of PaymentController.php. This makes it possible for unauthenticated attackers to mark unpaid ticket orders as completed by submitting a fabricated SureCart checkout ID or FluentCart cart hash, granting themselves paid event access, QR-code attendee tickets, and order confirmation emails without making any real payment. The wp_rest nonce required to reach the vulnerable endpoint is embedded in every public event page, meaning no WordPress session or credentials are needed to obtain it. This vulnerability represents a regression — the same function and endpoint were previously patched but the fix did not persist through subsequent releases.
Affected versions
max 4.1.16.
Status
vulnerable
Aug 01, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13178

CVE, Research URL

CVE-2026-13178

Date
Jul 30, 2026
Research Description
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
Affected versions
max 4.1.16.
Status
vulnerable
Aug 08, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-66451

CVE, Research URL

CVE-2026-66451

Date
Aug 06, 2026
Research Description
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Affected versions
max 4.1.10.
Status
vulnerable
Aug 12, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13170

CVE, Research URL

CVE-2026-13170

Date
Aug 10, 2026
Research Description
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
Affected versions
max 4.1.20.
Status
vulnerable
Aug 21, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13174

CVE, Research URL

CVE-2026-13174

Date
Aug 19, 2026
Research Description
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Affected versions
max 4.1.21.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13173

CVE, Research URL

CVE-2026-13173

Date
Aug 19, 2026
Research Description
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
Affected versions
max 4.1.21.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13169

CVE, Research URL

CVE-2026-13169

Date
Aug 19, 2026
Research Description
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.
Affected versions
max 4.1.21.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-13175

CVE, Research URL

CVE-2026-13175

Date
Aug 19, 2026
Research Description
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
Affected versions
max 4.1.21.
Status
vulnerable
Sep 07, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-84898

CVE, Research URL

CVE-2026-84898

Date
Sep 05, 2026
Research Description
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
Affected versions
max 4.1.21.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-84901

CVE, Research URL

CVE-2026-84901

Date
Sep 05, 2026
Research Description
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.
Affected versions
max 4.1.22.
Status
vulnerable
Sep 10, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-11821

CVE, Research URL

CVE-2026-11821

Date
Sep 09, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators.
Affected versions
max 4.1.18.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-15667

CVE, Research URL

CVE-2026-15667

Date
Sep 09, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
Affected versions
max 4.1.23.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-12956

CVE, Research URL

CVE-2026-12956

Date
Sep 09, 2026
Research Description
The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. This makes it possible for unauthenticated attackers to create etn-order posts with status='completed' that are counted as sold by etn_get_sold_tickets_by_event(); because the auto-cleanup wp_schedule_single_event() in create_item() only fires for status='pending' orders, the forged completed orders persist indefinitely and exhaust ticket inventory.
Affected versions
max 4.1.23.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-15406

CVE, Research URL

CVE-2026-15406

Date
Sep 09, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Affected versions
max 4.1.23.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-15398

CVE, Research URL

CVE-2026-15398

Date
Sep 09, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass payment for paid events, fraudulently mark orders as completed, deplete ticket inventory, and trigger confirmation emails for tickets never purchased. This is exploitable by unauthenticated attackers because the wp_rest nonce is publicly emitted on every frontend page, and the order creation endpoint mints and returns an order_access_token to any caller possessing that nonce — giving unauthenticated users all credentials required to reach the privileged update_booking_status branch.
Affected versions
max 4.1.23.
Status
vulnerable
Sep 15, 2026

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-75983

CVE, Research URL

CVE-2026-75983

Date
Sep 15, 2026
Research Description
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabilities. This makes it possible for authenticated attackers whose account is user ID 1, even subscribers, to pass every WordPress capability check, including `manage_options`, `edit_plugins`, `edit_themes`, `promote_users`, and `update_core`, thereby elevating their privileges to administrator-equivalent power and achieving full site takeover, including remote code execution via the plugin and theme editors. Exploitation is only impactful when user ID 1 has been deliberately demoted to a lower-privilege role as a common administrator-account hardening practice; on default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs.
Affected versions
max 4.1.24.
Status
vulnerable

Event Manager, Events Calendar, Events Tickets for WooCommerce &#8211; Eventin # CVE-2026-15402

CVE, Research URL

CVE-2026-15402

Date
Sep 15, 2026
Research Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 4.1.24.
Status
vulnerable