Description
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary emails with arbitrary content from the site.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16898 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary emails with arbitrary content from the site. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagauss
Metagauss eventprime |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:metagauss:eventprime:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Metagauss
Metagauss eventprime |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:45:43.967Z
Reserved: 2024-01-31T14:07:51.809Z
Link: CVE-2024-1124
Updated: 2024-08-01T18:26:30.510Z
Status : Modified
Published: 2024-03-09T07:15:08.000
Modified: 2026-04-08T18:20:27.817
Link: CVE-2024-1124
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD