### [CVE-2024-4665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4665) ![](https://img.shields.io/static/v1?label=Product&message=EventPrime&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=3.4.9%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-639%20Authorization%20Bypass%20Through%20User-Controlled%20Key&color=brightgreen) ### Description The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. ### POC #### Reference - https://wpscan.com/vulnerability/50b78cac-cad1-4526-9655-ae0440739796/ #### Github No PoCs found on GitHub currently.