Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure
2025-01-29 18:25
Whit TaylorStrategic Overview
StatusPatched in 5.18.1.1
Affected PluginEvent Tickets and Registration
Affected Version
<= 5.18.1CVSS5.3Medium
CVE
CVE-2024-13457Vulnerability Overview
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date.
Technical Analysis
REMEDIATION: Update to version 5.18.1.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C