Event Tickets and Registration, CVE-2024-13457
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jan 30, 2025
- Research Description
- The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date.
- Affected versions
-
Min -, max 5.18.1.1.
- Status
-
vulnerable