Description
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
Problem types
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
Product status
* (semver)
Timeline
| 2025-01-30: | Disclosed |
Credits
Ankit Patel
References
www.wordfence.com/...-be25-4269-9d3b-379309619bbe?source=cve
plugins.trac.wordpress.org/...es/widgets/htevent_sponsor.php