nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-2110 CVE-2024-2110
MEDIUM
Events Manager <= 6.4.7.1 - Cross-Site Request Forgery
Record summary
CVE-2024-2110 has a selected CVSS score of 4.3 (medium).
Description
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking statuses via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 28, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Events Manager – Calendar, Bookings, Tickets, and more!Browse netweblogic / Events Manager – Calendar, Bookings, Tickets, and more!Default status: unaffected | CVE List | Through 6.4.7.1 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3054883/events-manager/trunk/classes/em-bookings-table.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/c0538999-0a09-4d24-a530-a32fb5b4e5e6?source=cve