Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13216

Опубликовано: 31 янв. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

EPSS

Процентиль: 32%
0.00122
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 4.3
github
около 1 года назад

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

EPSS

Процентиль: 32%
0.00122
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-359