Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15306 | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. |
Thu, 13 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 27 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. |
Wed, 04 Jun 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagauss
Metagauss eventprime |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:metagauss:eventprime:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Metagauss
Metagauss eventprime |
Fri, 16 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. | |
| Title | EventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-13T21:00:08.476Z
Reserved: 2024-05-08T21:49:28.855Z
Link: CVE-2024-4665
Updated: 2025-05-16T15:15:16.483Z
Status : Modified
Published: 2025-05-15T20:15:54.557
Modified: 2025-11-13T21:15:48.050
Link: CVE-2024-4665
No data.
OpenCVE Enrichment
No data.
EUVD