1 results (0.007 seconds)
CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

CVE-2024-4665 – EventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update
https://notcve.org/view.php?id=CVE-2024-4665
15 May 2025 — The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. • https://wpscan.com/vulnerability/50b78cac-cad1-4526-9655-ae0440739796 •