The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Jun 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Awplife
Awplife event Monster |
|
CPEs | cpe:2.3:a:awplife:event_monster:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Awplife
Awplife event Monster |
Tue, 14 Jan 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 13 Jan 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number. | |
Title | Event monster <= 1.4.3 - Information Exposure Via Visitors List Export | |
Weaknesses | CWE-359 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-13T23:21:40.170Z
Updated: 2025-01-14T00:16:38.672Z
Reserved: 2024-11-18T23:57:28.793Z
Link: CVE-2024-11396

Updated: 2025-01-14T00:16:29.591Z

Status : Analyzed
Published: 2025-01-14T01:15:09.110
Modified: 2025-06-05T15:21:26.763
Link: CVE-2024-11396

No data.