CVE-2023-4252
27.11.2023, 17:15
The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.Enginsight
Vendor | Product | Version |
---|---|---|
metagauss | eventprime | 𝑥 ≤ 3.2.9 |
𝑥
= Vulnerable software versions