The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liquidweb
Liquidweb event Tickets |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:plus:wordpress:*:* | |
| Vendors & Products |
Liquidweb
Liquidweb event Tickets |
Thu, 27 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-03-04T21:00:09.049Z
Updated: 2025-03-27T16:48:48.662Z
Reserved: 2024-02-07T16:39:21.466Z
Link: CVE-2024-1319
Updated: 2024-08-01T18:33:25.378Z
Status : Analyzed
Published: 2024-03-04T21:15:07.083
Modified: 2025-04-24T15:15:11.847
Link: CVE-2024-1319
No data.