CVE-2024-11396
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 2.02%
- CWE
- CWE-359
- Published
- 2025-01-13
- Last modified
- 2026-04-08
Affected products
- awordpresslife Event Monster – Event Management, Tickets Booking, Upcoming Event
- awordpresslife Event Monster – Manager & Ticket Booking
Weakness type
Related vulnerabilities
- CVE-2022-0482 — Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
- CVE-2024-45591 — XWiki Platform document history including authors of any page exposed to unauthorized actors
- CVE-2023-50719 — XWiki Platform Solr search discloses password hashes of all users
- CVE-2022-2921 — Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp
- CVE-2022-1365 — Exposure of Private Personal Information to an Unauthorized Actor in lquixada/cross-fetch
- CVE-2024-45787 — Information Disclosure Vulnerability
- CVE-2025-54125 — XWiki Platform: Password and email exposure in xml.vm fields
- CVE-2025-53625 — DynamicPageList3 exposes hidden/suppressed usernames