EventPrime <= 3.3.2 - Improper Server-Side Checks to Booking Payment Bypass

2023-10-30 00:00
Alex Sanford

Strategic Overview

Vulnerability Overview

The EventPrime plugin for WordPress is vulnerable to booking payment bypass in all versions up to, and including, 3.3.2. This is due to the plugin relying on user supplied input to control pricing instead of server-side controls/validation. This makes it possible for unauthenticated attackers to make bookings paying less than the expected amount for a booking.

Technical Analysis

REMEDIATION: Update to version 3.3.3, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C