Information Exposure in Event Management Plugin for WordPress
CVE-2024-11396
5.3MEDIUM
Summary
The Event Monster plugin for WordPress is susceptible to an Information Exposure vulnerability that could jeopardize sensitive visitor information. All versions up to and including 1.4.3 create a publicly accessible CSV file during the export of the Visitors List, which is stored in the wp-content directory. This file is generated with a hardcoded filename, allowing unauthenticated attackers to obtain personal data, such as first names, last names, email addresses, and phone numbers of event attendees. The lack of proper access controls significantly increases the risk of data breaches through this exposure.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published