CVE-2023-6447
22.01.2024, 20:15
The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.Enginsight
Vendor | Product | Version |
---|---|---|
metagauss | eventprime | 𝑥 < 3.3.6 |
𝑥
= Vulnerable software versions