Cyber Resilience

CVE-2024-1316

MediumPublic PoC

Published: 04 March 2024

Published
04 March 2024
Modified
27 June 2025
KEV Added
Patch
CVSS Score v3.1 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0070 72.5th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-1316 is a medium-severity an unspecified weakness vulnerability in Liquidweb Event Tickets. Its CVSS base score is 6.5 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Information Repositories (T1213); ranked in the top 27.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft,…

more

private, pending review, pw-protected, and trashed events).

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1213 Data from Information Repositories Collection
Adversaries may leverage information repositories to mine valuable information.
Why these techniques?

The vulnerability is a broken access control issue allowing low-privileged (contributor+) authenticated users to leak existence and details of restricted events (draft, private, etc.) via shortcodes, enabling collection of data from the WordPress information repository.

Affected Assets

liquidweb
event tickets
≤ 5.8.1 · ≤ 5.9.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References