The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17077 | The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liquidweb
Liquidweb event Tickets |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:plus:wordpress:*:* | |
| Vendors & Products |
Liquidweb
Liquidweb event Tickets |
Thu, 27 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-27T16:48:48.662Z
Reserved: 2024-02-07T16:39:21.466Z
Link: CVE-2024-1319
Updated: 2024-08-01T18:33:25.378Z
Status : Analyzed
Published: 2024-03-04T21:15:07.083
Modified: 2025-04-24T15:15:11.847
Link: CVE-2024-1319
No data.
OpenCVE Enrichment
No data.
EUVD