Input validation vulnerability in EventPrime – Events Calendar, Bookings and Tickets 3.2.0

The EventPrime plugin for WordPress is vulnerable to a form of attack called Cross-Site Request Forgery in versions up to 3.2.0. This is because its security system does not properly validate requests made by users. This means that unauthenticated attackers can create event bookings on a website by tricking the site administrator into clicking on a malicious link. A duplicate security identifier (CVE-2023-5519) has been assigned to this issue.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.