Beveiligingsadvies

CVE-2024-1319

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-03-04 21:00:09
Laatst bijgewerkt 2025-03-27 16:48:48
Toegewezen door WPScan
CVSS-score 4.3
Status PUBLISHED

Beschrijving

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).