EventPrime – Events Calendar, Bookings and Tickets, CVE-2023-4252
- CVE, Research URL
- Published on
- Nov 27, 2023
- Research Description
- The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
- Affected versions
-
Min -, max 3.3.3.
- Status
-
vulnerable