VYPR

Ekc Tournament Manager

by Lukashuser

Source repositories

CVEs (3)

  • CVE-2024-9765MedMay 15, 2025
    risk 0.35cvss 6.5epss 0.02

    The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

  • CVE-2024-9711MedMay 15, 2025
    risk 0.28cvss 5.4epss 0.00

    The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-9709MedMay 15, 2025
    risk 0.28cvss 5.4epss 0.00

    The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack