Deserialization of Untrusted Data Vulnerability Affects MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce - WpEvently - WordPress Plugin
CVE-2024-24796

8.8HIGH

Summary

The MagePeople Event Manager and Tickets Selling Plugin for WooCommerce is susceptible to a deserialization of untrusted data vulnerability. This flaw allows attackers to potentially execute arbitrary PHP code, leading to severe security implications. Specifically, it affects versions from the initial release through 4.1.1, threatening the integrity and confidentiality of the WordPress sites that utilize this plugin. Site administrators are urged to review the plugin's configurations and verify they are not running an affected version to safeguard against potential exploitation.

Affected Version(s)

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin <= 4.1.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NGÔ THIÊN AN / ancorn_ from VNPT-VCI (Patchstack Alliance)
.