The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.
Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Metagauss
Metagauss eventprime |
|
CPEs | cpe:2.3:a:metagauss:eventprime:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Metagauss
Metagauss eventprime |
Tue, 17 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Dec 2024 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page. Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default. | |
Title | EventPrime – Events Calendar, Bookings and Tickets <= 4.0.5.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-17T09:22:41.540Z
Updated: 2024-12-17T17:29:41.507Z
Reserved: 2024-12-02T14:36:59.586Z
Link: CVE-2024-12024
Vulnrichment
Updated: 2024-12-17T15:42:32.435Z
NVD
Status : Analyzed
Published: 2024-12-17T10:15:05.643
Modified: 2025-01-10T17:56:30.330
Link: CVE-2024-12024
Redhat
No data.