🔐 CVE Alert

CVE-2024-11396

MEDIUM 5.3

Event monster <= 1.4.3 - Information Exposure Via Visitors List Export

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

CWE CWE-359
Vendor awordpresslife
Product event monster – manager & ticket booking
Published Jan 13, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for awordpresslife event monster – manager & ticket booking

Be the first to know when new medium vulnerabilities affecting awordpresslife event monster – manager & ticket booking are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

awordpresslife / Event Monster – Manager & Ticket Booking
0 ≤ 1.4.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/0f522dfe-f2c2-4adb-980c-1f03d3c26e12?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/event-monster/tags/1.4.3/em-ajax-prossesing/em-visitor-ajax.php#L92

Credits

mike harris