CVE-2024-9765: Lukashuser Ekc Tournament Manager
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
Affected products
- Lukashuser Ekc Tournament Manager: before 2.2.2 (fixed in 2.2.2)
Published 2025-05-15. Last modified 2026-06-17.