VYPR

Ekc Tournament Manager

by WordPress

Source repositories

CVEs (4)

  • CVE-2024-49674CriOct 31, 2024
    risk 0.55cvss 9.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through <= 2.2.1.

  • CVE-2024-9765MedMay 15, 2025
    risk 0.35cvss 6.5epss 0.02

    The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

  • CVE-2024-9711MedMay 15, 2025
    risk 0.28cvss 5.4epss 0.00

    The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-9709MedMay 15, 2025
    risk 0.28cvss 5.4epss 0.00

    The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack