cleantalk
Vulnerabilities and Security Researches

Event Tickets and Registration, CVE-2024-1316

CVE, Research URL

CVE-2024-1316

Published on
Mar 05, 2024
Research Description
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
Affected versions
Min -, max 5.8.1.
Status
vulnerable