Information Exposure in Event Management Plugin for WordPress
CVE-2024-11396
5.3MEDIUM
What is CVE-2024-11396?
The Event Monster plugin for WordPress is susceptible to an Information Exposure vulnerability that could jeopardize sensitive visitor information. All versions up to and including 1.4.3 create a publicly accessible CSV file during the export of the Visitors List, which is stored in the wp-content directory. This file is generated with a hardcoded filename, allowing unauthenticated attackers to obtain personal data, such as first names, last names, email addresses, and phone numbers of event attendees. The lack of proper access controls significantly increases the risk of data breaches through this exposure.