CVE-2024-2110

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking statuses via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 11,858 live websites that are affected by CVE-2024-2110.

Test my site




Affected Software

Product  Events Manager for WordPress
Category Wordpress Plugins
Vulnerable Domains11,858 live websites (30.88% of Events Manager for WordPress install base)
Vulnerable Versions
  • from 0 through 6.4.7.1
Vulnerable Versions Count83 versions ( 71.55% of all versions)



Details

  • Published - Mar 28, 2024
  • Updated - Aug 1, 2024

Credits

  • Tim Coen (finder)

CVE-2024-2110 usage by Country

United States3,437 websites



Germany2,211 websites
France1,096 websites
GB464 websites
Netherlands462 websites
Italy395 websites
Japan377 websites
Switzerland279 websites
Spain264 websites
Poland193 websites

CVE-2024-2110 usage by TLD

.com3,395 websites
.de1,438 websites
.org1,434 websites
.fr503 websites
.nl441 websites
.it332 websites
.co.uk260 websites
.net249 websites
.ch239 websites
.at200 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2110

Top websites that are affected by CVE-2024-2110. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*******.**********.it Italy**,***
*********.*******.org United States**,***
******.***.uk United States**,***
*******.org United States**,***
********.org United States**,***
*****.***.edu United States**,***
****.**.in United States**,***
********************.com United States**,***
*************.cat Spain***,***
**************.it Italy***,***
See full domain list

FAQ

A total of 11,858 websites have been identified as vulnerable to CVE-2024-2110, discovered through global website indexing conducted by WebTechSurvey.
Events Manager for WordPress is susceptible to CVE-2024-2110 vulnerability.
Events Manager for WordPress versions before, and including, 6.4.7.1 are vulnerable to CVE-2024-2110.