The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Feb 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 31 Jan 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data. | |
Title | HT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: Sponsor | |
Weaknesses | CWE-359 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-10T22:07:42.735Z
Reserved: 2025-01-08T17:53:52.031Z
Link: CVE-2024-13216

Updated: 2025-01-31T15:36:48.504Z

Status : Received
Published: 2025-01-31T06:15:28.267
Modified: 2025-01-31T06:15:28.267
Link: CVE-2024-13216

No data.