The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
2023-11-27T17:15:08.517
2024-11-21T08:34:43.910
Modified
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | metagauss | eventprime | ≤ 3.2.9 | Yes |