EventPrime <= 3.3.2 - Improper Server-Side Checks to Booking Payment Bypass
Strategic Overview
<= 3.3.2CVE-2023-4252Vulnerability Overview
The EventPrime plugin for WordPress is vulnerable to booking payment bypass in all versions up to, and including, 3.3.2. This is due to the plugin relying on user supplied input to control pricing instead of server-side controls/validation. This makes it possible for unauthenticated attackers to make bookings paying less than the expected amount for a booking.
Technical Analysis
REMEDIATION: Update to version 3.3.3, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C