CVE-2024-10799

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 22

Summary

CVE-2024-10799 is a newly disclosed vulnerability affecting the Eventer plugin for WordPress. This issue allows authenticated attackers with Subscriber-level access or higher to traverse directories using the eventer_woo_download_tickets() function. By exploiting this vulnerability, attackers can read the contents of arbitrary files on the server, potentially gaining access to sensitive information. The vulnerability impacts all versions of Eventer up to and including 3.9.7. WordPress users are strongly advised to update the plugin to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share