S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 25, 2025

CVE-2024-11396 Scanner

Event Monster <= 1.4.3 - Information Exposure Via Visitors List Export CVE-2024-11396 Scanner

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-11396
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Event Monster – Manager & Ticket Bookingby awordpresslife
0
Updated Aug 22, 2026View on NVD →
Detail

The Event Monster plugin is a widely-used tool for event management, ticket booking, and upcoming event management in WordPress. It allows users to manage event details and ticket sales. This plugin is employed by WordPress site administrators to facilitate event registration and attendance. Event Monster offers a range of features, including the ability to export event visitor information. The software is generally used by event organizers to track attendee data. However, a vulnerability has been identified in versions up to 1.4.3, making it prone to information leakage.

This vulnerability occurs due to an insecurely exposed CSV file containing sensitive visitor data. The CSV file is created when an event's visitors list is exported. The file is stored in the wp-content directory with a hardcoded filename, making it accessible to anyone who knows the URL. Attackers can download the file and retrieve personal information, such as names, emails, and phone numbers, without authentication. This represents a significant privacy risk to event attendees. The issue exists in all versions up to and including 1.4.3 of the Event Monster plugin.

The vulnerability arises from improper file handling and a lack of authorization control during the export process. When the visitors list is exported, a CSV file is generated in the wp-content folder, which can be accessed publicly. The filename is hardcoded, and no authentication is required to access it. This allows attackers to access personal information about event attendees. The vulnerability is triggered when an attacker sends a GET request to the wp-content/uploads/visitors-list.csv URL. As the file contains sensitive data like first and last names, emails, and phone numbers, its exposure could lead to privacy violations.

If exploited, this vulnerability can lead to significant information exposure. Attackers could extract sensitive personal information of event attendees. This could result in privacy breaches, identity theft, or phishing attacks. The leaked information could be used to target victims with spam, scams, or other malicious activities. In some cases, it could damage the reputation of the event organizers. The exposed data may also lead to legal or compliance issues related to privacy regulations.

References:

Solution Advice
  • Update the Event Monster plugin to version 1.4.4 or later to patch the vulnerability.
  • Ensure that sensitive files, such as exported visitor lists, are not stored in publicly accessible directories.
  • Implement proper access control mechanisms for files that contain sensitive data.
  • Regularly monitor the server for unauthorized access attempts or unusual activities.
  • Consider reviewing your overall event management system for other potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.