// For flags

CVE-2023-27437

WordPress Event Espresso 4 Decaf plugin <= 4.10.44.decaf - Bypass vulnerability

Severity Score

3.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.

Vulnerabilidad de falta de autorizaciĆ³n en Event Espresso Event Espresso 4 Decaf permite un uso indebido de la funcionalidad. Este problema afecta a Event Espresso 4 Decaf: desde n/a hasta 4.10.44.Decaf.

The Event Espresso 4 Decaf plugin for WordPress is vulnerable to bypass of a plugin feature in versions up to, and including, 4.10.44.decaf. This is due to incorrect validation of the number of tickets ordered per order when making a ticket purchase. This makes it possible for unauthenticated individuals to purchase more tickets than the maximum allowed per order.

*Credits: yuyudhn (Patchstack Alliance)
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-03-01 CVE Reserved
  • 2023-03-05 CVE Published
  • 2024-06-04 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-354: Improper Validation of Integrity Check Value
  • CWE-862: Missing Authorization
CAPEC
  • CAPEC-212: Functionality Misuse
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Event Espresso Decaf
Search vendor "Event Espresso Decaf"
Event Espresso Decaf
Search vendor "Event Espresso Decaf" for product "Event Espresso Decaf"
>= 0.0.0.0 <= 4.10.44.decaf
Search vendor "Event Espresso Decaf" for product "Event Espresso Decaf" and version " >= 0.0.0.0 <= 4.10.44.decaf"
en
Affected