Medium severity5.3NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026
CVE-2024-11396
CVE-2024-11396
Description
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.4.3
- awordpresslife/Event Monster – Manager & Ticket Bookingv5Range: 0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.