CVE-2024-4665: Metagauss Eventprime
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.
Affected products
- Metagauss Eventprime: before 3.5.0 (fixed in 3.5.0)
Published 2025-05-15. Last modified 2026-06-17.