Cross-Site Request Forgery Vulnerability in The Events Calendar Event Tickets by Modern Tribe
CVE-2024-38762

4.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
2 January 2025

Summary

The vulnerability enables attackers to initiate unauthorized requests on behalf of users without their consent, leveraging the Event Tickets plugin within The Events Calendar ecosystem. This Cross-Site Request Forgery (CSRF) issue affects all versions of Event Tickets up to and including 5.11.0.4, exposing users to potential transactional exploits and unauthorized actions. It is crucial for users to apply security measures and updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Event Tickets <= 5.11.0.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Chan (Patchstack Alliance)
.