CVE-2024-38762

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-38762 represents a Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar Event Tickets plugin. This issue enables attackers to manipulate user actions on affected websites by tricking them into making unintended requests. The affected versions of The Events Calendar Event Tickets range from n/a to 5.11.0.4. Successful exploitation could lead to unauthorized modifications or data exfiltration. Users are advised to update to the latest version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share