CVE-2024-10799
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-10799 is a newly disclosed vulnerability affecting the Eventer plugin for WordPress. This issue allows authenticated attackers with Subscriber-level access or higher to traverse directories using the eventer_woo_download_tickets() function. By exploiting this vulnerability, attackers can read the contents of arbitrary files on the server, potentially gaining access to sensitive information. The vulnerability impacts all versions of Eventer up to and including 3.9.7. WordPress users are strongly advised to update the plugin to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.