CVE-2024-9765: Lukashuser Ekc Tournament Manager

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

Affected products

  • Lukashuser Ekc Tournament Manager: before 2.2.2 (fixed in 2.2.2)

Published 2025-05-15. Last modified 2026-06-17.