CVE-2024-1376
24.05.2024, 07:15
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with subscriber access or higher, to update post_meta_data.Enginsight
Vendor | Product | Version |
---|---|---|
avecnous | event_post | 𝑥 < 5.9.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References