Metagauss
Metagauss Eventprime: vulnerabilidades y CVE
Metagauss Eventprime tiene 34 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE34
Últimos 12 meses7
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24378 | Crítica (9.8) | 0.51% | — | 25 mar 2026 | Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0. |
| CVE-2025-69358 | Alta (7.5) | 0.31% | — | 25 mar 2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <=… |
| CVE-2026-25312 | Alta (7.5) | 0.21% | — | 19 mar 2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <=… |
| CVE-2026-25389 | Media (5.3) | 0.25% | — | 19 feb 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects… |
| CVE-2026-24380 | Media (5.3) | 0.21% | — | 22 ene 2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <=… |
| CVE-2025-63007 | Media (4.3) | 0.26% | — | 9 dic 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <=… |
| CVE-2025-63006 | Media (4.3) | 0.21% | — | 9 dic 2025 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <=… |
| CVE-2024-4665 | Media (6.4) | 0.30% | — | 15 may 2025 | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. |
| CVE-2024-13526 | Media (4.3) | 0.29% | — | 7 mar 2025 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up… |
| CVE-2024-12024 | Media (6.1) | 0.42% | — | 17 dic 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to,… |
| CVE-2024-43223 | Alta (8.8) | 0.40% | — | 1 nov 2024 | Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2. |
| CVE-2024-9865 | Media (6.1) | 0.39% | — | 24 oct 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to… |
| CVE-2024-9864 | Media (6.1) | 0.32% | — | 24 oct 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input… |
| CVE-2024-8369 | Media (5.3) | 0.35% | — | 10 sept 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and… |
| CVE-2024-31275 | Crítica (9.8) | 0.47% | — | 9 jun 2024 | Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4. |
| CVE-2023-33321 | Media (5.3) | 0.52% | — | 17 may 2024 | Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6. |
| CVE-2024-29776 | Media (4.8) | 0.36% | — | 27 mar 2024 | Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. |
| CVE-2024-24832 | Alta (7.5) | 0.44% | — | 23 mar 2024 | Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. |
| CVE-2024-1321 | Media (5.3) | 0.26% | — | 13 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update… |
| CVE-2024-1127 | Media (4.3) | 0.53% | — | 13 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_all() function in all versions up to, and… |
| CVE-2024-1126 | Media (4.3) | 0.44% | — | 13 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_email_by_event_id() function in all… |
| CVE-2024-1320 | Media (6.1) | 0.37% | — | 9 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up to, and including, 3.4.3 due to insufficient… |
| CVE-2024-1125 | Media (5.3) | 0.32% | — | 9 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the calendar_events_delete() function in all versions up to,… |
| CVE-2024-1124 | Media (4.3) | 0.32% | — | 9 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to,… |
| CVE-2024-1123 | Media (6.5) | 0.41% | — | 9 mar 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all… |
| CVE-2023-6447 | Media (5.3) | 0.56% | — | 22 ene 2024 | The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name. |
| CVE-2023-4252 | Media (5.3) | 0.54% | — | 27 nov 2023 | The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment. |
| CVE-2023-5519 | Media (4.3) | 0.20% | — | 31 oct 2023 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. |
| CVE-2023-5238 | Media (6.1) | 0.42% | — | 31 oct 2023 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website. |
| CVE-2023-4251 | Media (4.3) | 0.23% | — | 31 oct 2023 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.