Eventer
cpe:2.3:a:imithemes:eventer:*:*:*:*:wordpress:*:*
- <= 3.9.9.5
A vulnerability exists in the Eventer plugin for WordPress, specifically in versions through 3.9.9.5, due to a lack of proper capability checks in the 'handle_pdf_download_request' function. This oversight allows unauthenticated users to download event tickets, unauthorized access to event ticket data.
Exploitation of this vulnerability allows for unauthorized downloading of event tickets, potentially leading to misuse of event registration or access privileges.
Users can update to version 3.9.9.5.1 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.