CVE-2023-27437
WordPress Event Espresso 4 Decaf plugin <= 4.10.44.decaf - Bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.
Vulnerabilidad de falta de autorizaciĆ³n en Event Espresso Event Espresso 4 Decaf permite un uso indebido de la funcionalidad. Este problema afecta a Event Espresso 4 Decaf: desde n/a hasta 4.10.44.Decaf.
The Event Espresso 4 Decaf plugin for WordPress is vulnerable to bypass of a plugin feature in versions up to, and including, 4.10.44.decaf. This is due to incorrect validation of the number of tickets ordered per order when making a ticket purchase. This makes it possible for unauthenticated individuals to purchase more tickets than the maximum allowed per order.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-03-01 CVE Reserved
- 2023-03-05 CVE Published
- 2024-06-04 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-354: Improper Validation of Integrity Check Value
- CWE-862: Missing Authorization
CAPEC
- CAPEC-212: Functionality Misuse
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/event-espresso-decaf/wordpress-event-espresso-4-decaf-plugin-4-10-44-decaf-bypass-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Event Espresso Decaf Search vendor "Event Espresso Decaf" | Event Espresso Decaf Search vendor "Event Espresso Decaf" for product "Event Espresso Decaf" | >= 0.0.0.0 <= 4.10.44.decaf Search vendor "Event Espresso Decaf" for product "Event Espresso Decaf" and version " >= 0.0.0.0 <= 4.10.44.decaf" | en |
Affected
|