Vulnerabilities > Imithemes > Eventer > 2.4.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-03 | CVE-2024-11132 | Cross-site Scripting vulnerability in Imithemes Eventer The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-03 | CVE-2024-11133 | Missing Authorization vulnerability in Imithemes Eventer The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9. | 5.3 |
2025-02-03 | CVE-2024-11134 | Missing Authorization vulnerability in Imithemes Eventer The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9.9. | 6.5 |
2025-01-28 | CVE-2024-11135 | SQL Injection vulnerability in Imithemes Eventer The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, 3.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |