🔐 CVE Alert

CVE-2024-1321

MEDIUM 5.3

EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events for free.

CWE CWE-345
Vendor metagauss
Product eventprime – events calendar, bookings and tickets
Published Mar 13, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for metagauss eventprime – events calendar, bookings and tickets

Be the first to know when new medium vulnerabilities affecting metagauss eventprime – events calendar, bookings and tickets are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

metagauss / EventPrime – Events Calendar, Bookings and Tickets
0 ≤ 3.4.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/765d0933-8db2-471c-ad4e-e19d3b4ff015?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3033882%40eventprime-event-calendar-management&new=3033882%40eventprime-event-calendar-management&sfp_email=&sfph_mail=

Credits

Lucio Sá