CVE Vulnerabilities

CVE-2023-6447

Published: Jan 22, 2024 | Modified: Jun 17, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

Affected Software

NameVendorStart VersionEnd Version
EventprimeMetagauss*3.3.6 (excluding)

References