Stored Cross-Site Scripting Vulnerability in EventPrime for WordPress Plugin
CVE-2024-12024
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 December 2024
What is CVE-2024-12024?
CVE-2024-12024 refers to a significant stored Cross-Site Scripting (XSS) vulnerability present in the EventPrime plugin for WordPress. This vulnerability allows unauthenticated attackers to exploit the em_ticket_category_data and em_ticket_individual_data parameters due to inadequate input sanitization and output escaping present in all versions up to and including 4.0.5.3. If the 'Guest Submissions' feature is enabled, malicious scripts can be injected into pages, triggering execution whenever an administrative user visits a compromised page. Given the potential for extensive exploitation, this vulnerability poses a critical security risk to websites utilizing the EventPrime plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EventPrime β Events Calendar, Bookings and Tickets * <= 4.0.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved