Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6p5x-4w46-32gx

Опубликовано: 15 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

EPSS

Процентиль: 17%
0.00053
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
nvd
9 месяцев назад

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

EPSS

Процентиль: 17%
0.00053
Низкий

5.3 Medium

CVSS3