The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page. Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default.
History

Fri, 10 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss eventprime
CPEs cpe:2.3:a:metagauss:eventprime:*:*:*:*:*:wordpress:*:*
Vendors & Products Metagauss
Metagauss eventprime

Tue, 17 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Dec 2024 09:45:00 +0000

Type Values Removed Values Added
Description The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page. Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default.
Title EventPrime – Events Calendar, Bookings and Tickets <= 4.0.5.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-17T09:22:41.540Z

Updated: 2024-12-17T17:29:41.507Z

Reserved: 2024-12-02T14:36:59.586Z

Link: CVE-2024-12024

cve-icon Vulnrichment

Updated: 2024-12-17T15:42:32.435Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-17T10:15:05.643

Modified: 2025-01-10T17:56:30.330

Link: CVE-2024-12024

cve-icon Redhat

No data.