The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jan 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 13 Jan 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number. | |
Title | Event monster <= 1.4.3 - Information Exposure Via Visitors List Export | |
Weaknesses | CWE-359 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-14T00:16:38.672Z
Reserved: 2024-11-18T23:57:28.793Z
Link: CVE-2024-11396

Updated: 2025-01-14T00:16:29.591Z

Status : Received
Published: 2025-01-14T01:15:09.110
Modified: 2025-01-14T01:15:09.110
Link: CVE-2024-11396

No data.