CVE-2024-1053
CVE-2024-1053 allows unauthorized access to attendee data in the Event Tickets and Registration WordPress plugin. This vulnerability affects versions 5.8.1 and earlier, potentially exposing sensitive information to attackers. Specifically, authenticated users with contributor-level access or higher can exploit the missing capability check on the 'email' action to email the entire attendee list to themselves, violating data privacy. The SVRS score of 30 suggests a moderate risk, however, it's crucial to implement security measures due to the potential for data breaches and compliance violations. While the CVSS score is 0, indicating minimal immediate technical impact, the unauthorized data access elevates the overall risk profile and should be mitigated. This vulnerability is significant because it can lead to unauthorized disclosure of personal information, potentially causing harm to both the organization and its attendees, which can have considerable compliance consequences. Immediate patching of the Event Tickets and Registration plugin is recommended to prevent exploitation of this vulnerability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.