The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
History

Fri, 27 Jun 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Liquidweb
Liquidweb event Tickets
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:plus:wordpress:*:*
Vendors & Products Liquidweb
Liquidweb event Tickets

Wed, 28 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-04T21:00:09.876Z

Updated: 2024-08-28T15:21:35.718Z

Reserved: 2024-02-07T16:09:47.068Z

Link: CVE-2024-1316

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.700Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-04T21:15:07.007

Modified: 2025-06-27T14:13:27.050

Link: CVE-2024-1316

cve-icon Redhat

No data.