The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
CVE ID: CVE-2024-1319
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
Vendor: Unknown
Product: Events Tickets Plus
EPSS Score: 0.1% (probability of being exploited)
EPSS Percentile: 28.96% (scored less or equal to compared to others)
EPSS Date: 2025-04-21 (when was this score calculated)
SSVC Exploitation: poc
SSVC Technical Impact: partial
SSVC Automatable: false