CVE · Medium

CVE-2024-1122 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 3.3.51

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1122 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 3.3.51 Missing Authorization Medium 5.3 < 3.3.51 3.3.51 2024-02-08

CVE-2024-1122

The Eventin event management plugin for WordPress contained a broken access control vulnerability affecting versions prior to 3.3.51, where missing authorization checks allowed unauthenticated or low-privileged users to perform actions normally restricted to higher-privileged accounts. Researcher Francesco Carlucci identified the flaw, which stemmed from inadequate nonce verification and authentication controls in plugin functions. The vulnerability was resolved in version 3.3.51, and users should upgrade immediately to eliminate the security risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.