Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure

2025-01-29 18:25
Whit Taylor

Strategic Overview

Status
Patched in 5.18.1.1
Affected Version<= 5.18.1
CVSS5.3Medium
CVECVE-2024-13457
View all Event Tickets and Registration vulnerabilities

Vulnerability Overview

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date.

Technical Analysis

REMEDIATION: Update to version 5.18.1.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C