nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-2261 CVE-2024-2261
MEDIUM
Event Tickets and Registration <= 5.8.2 - Improper Authorization to Information Disclosure
Record summary
CVE-2024-2261 has a selected CVSS score of 4.3 (medium).
Description
The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street addresses.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 25, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Event Tickets and RegistrationBrowse stellarwp / Event Tickets and RegistrationDefault status: unaffected | CVE List | Through 5.8.2 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?old_path=/event-tickets/tags/5.8.2&old=3059268&new_path=/event-tickets/tags/5.8.3&new=3059268&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/2e42dd1c-adf7-471a-a14a-9038c56413a2?source=cve