The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Eventprime |
Metagauss |
* |
3.2.9 (including) |
References