CVE-2024-11134
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 3, 2025
CWE ID 862
Summary
CVE-2024-11134 is a vulnerability affecting the Eventer plugin for WordPress. The issue lies within the 'eventer_export_bookings_csv' function, which lacks proper capability checks. Consequently, authenticated attackers with subscriber-level permissions or above can exploit this vulnerability to gain unauthorized access to customers' personal data by downloading bookings. This puts at risk the privacy and security of the affected WordPress websites. Users are advised to update to the latest version of the Eventer plugin to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share