Event Espresso 4 Decaf <= 4.10.44.decaf - Feature Bypass

2023-03-05 00:00
yuyudhn

Strategic Overview

Status
Patched in 4.10.45.decaf
Affected Version<= 4.10.44.decaf
CVSS5.3Medium
CVECVE-2023-27437
View all Event Espresso – Event Registration & Ticketing Sales vulnerabilities

Vulnerability Overview

The Event Espresso 4 Decaf plugin for WordPress is vulnerable to bypass of a plugin feature in versions up to, and including, 4.10.44.decaf. This is due to incorrect validation of the number of tickets ordered per order when making a ticket purchase. This makes it possible for unauthenticated individuals to purchase more tickets than the maximum allowed per order.

Technical Analysis

REMEDIATION: Update to version 4.10.45.decaf, or a newer patched version --- IDENTIFIER: CWE-354 (Improper Validation of Integrity Check Value) The product does not validate or incorrectly validates the integrity check values or checksums of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C