CVE-2024-4665: Metagauss Eventprime

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

Affected products

  • Metagauss Eventprime: before 3.5.0 (fixed in 3.5.0)

Published 2025-05-15. Last modified 2026-06-17.