CVE-2024-1321
Last modified
CVE-2024-1321 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events for free.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metagauss | Eventprime | < 3.4.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1321?
How severe is CVE-2024-1321?
How do I fix CVE-2024-1321?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13204A vulnerability was found in kurniaramadhan E-Commerce-PHP 1…8
- CVE-2024-13205A vulnerability was found in kurniaramadhan E-Commerce-PHP 1…5.4
- CVE-2024-13206A vulnerability classified as critical has been found in REV…8.5
- CVE-2024-13207The Widget for Social Page Feeds WordPress plugin before 6.4…4.8
- CVE-2024-13208The Maps Plugin using Google Maps for WordPress WordPress p…4.3
- CVE-2024-13209A vulnerability was found in Redaxo CMS 5.18.1. It has been …5.4
- CVE-2024-13210A vulnerability was found in donglight bookstore电商书城系统说明 1.0…7.2
- CVE-2024-13211A vulnerability was found in SingMR HouseRent 1.0. It has be…8.8
- CVE-2024-13212A vulnerability classified as critical has been found in Sin…8.8
- CVE-2024-13213A vulnerability classified as problematic was found in SingM…5.4
- CVE-2024-13215The Elementor Addon Elements plugin for WordPress is vulnera…4.3
- CVE-2024-13216The HT Event – WordPress Event Manager Plugin for Elementor …4.3
Are you affected by CVE-2024-1321?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
