cve/2024/CVE-2024-4665.md
2025-09-29 16:08:36 +00:00

760 B

CVE-2024-4665

Description

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

POC

Reference

Github

No PoCs found on GitHub currently.