Metrics
Affected Vendors & Products
Wed, 08 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:imithemes:eventer:*:*:*:*:*:wordpress:*:* |
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9. This makes it possible for unauthenticated attackers to download event tickets. | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9.5. This makes it possible for unauthenticated attackers to download event tickets. |
| Title | Eventer <= 3.9.9 - Missing Authorization to Unauthenticated Event Ticket Download | Eventer <= 3.9.9.5 - Missing Authorization to Unauthenticated Event Ticket Download |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 03 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Feb 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9. This makes it possible for unauthenticated attackers to download event tickets. | |
| Title | Eventer <= 3.9.9 - Missing Authorization to Unauthenticated Event Ticket Download | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:40:36.793Z
Reserved: 2024-11-12T10:32:19.526Z
Link: CVE-2024-11133
Updated: 2025-02-03T20:20:17.927Z
Status : Modified
Published: 2025-02-03T20:15:32.203
Modified: 2026-04-08T17:17:37.170
Link: CVE-2024-11133
No data.