CVE-2024-52427
WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.
La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un motor de plantillas en Saso Nikolov Event Tickets con Ticket Scanner permite la inyección de Server Side Include (SSI). Este problema afecta a Event Tickets con Ticket Scanner: desde n/a hasta 2.3.11.
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.11. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-11-11 CVE Reserved
- 2024-11-15 CVE Published
- 2024-11-21 CVE Updated
- 2024-11-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
CAPEC
- CAPEC-101: Server Side Include (SSI) Injection
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Event Tickets With Ticket Scanner Search vendor "Event Tickets With Ticket Scanner" | Event Tickets With Ticket Scanner Search vendor "Event Tickets With Ticket Scanner" for product "Event Tickets With Ticket Scanner" | >= 0.0.0 <= 2.3.11 Search vendor "Event Tickets With Ticket Scanner" for product "Event Tickets With Ticket Scanner" and version " >= 0.0.0 <= 2.3.11" | en |
Affected
|