CVE-2023-6447

Publication date

2024-01-22 19:14:30

Family

WPScan

State

PUBLISHED

Description

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.