CVE-2023-4251: Metagauss Eventprime

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.

Affected products

  • Metagauss Eventprime: before 3.2.0 (fixed in 3.2.0)

Published 2023-10-31. Last modified 2026-06-17.