Описание
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.8.1 (исключая)Версия до 5.9.1 (исключая)
Одно из
cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:plus:wordpress:*:*
EPSS
Процентиль: 65%
0.00494
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 6.5
github
почти 2 года назад
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
EPSS
Процентиль: 65%
0.00494
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo