CVE Database /
CVE-2024-1122
CVE · Medium
CVE-2024-1122 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 3.3.51
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1122
|
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 3.3.51 |
Missing Authorization |
Medium
5.3
|
< 3.3.51
|
3.3.51 |
2024-02-08 |
—
|
CVE-2024-1122
The Eventin event management plugin for WordPress contained a broken access control vulnerability affecting versions prior to 3.3.51, where missing authorization checks allowed unauthenticated or low-privileged users to perform actions normally restricted to higher-privileged accounts. Researcher Francesco Carlucci identified the flaw, which stemmed from inadequate nonce verification and authentication controls in plugin functions. The vulnerability was resolved in version 3.3.51, and users should upgrade immediately to eliminate the security risk.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings