Junglewise Threat Intelligence

CVE-2024-32110: Magepeople WpEvently CSRF in WordPress plugin

CVE-2024-32110 · Severity: medium · CVSS 4.3 · Published 2026-06-11

Technologies: MagePeople WpEvently. Vendors: Magepeople inc., MagePeople.

Executive brief

WpEvently is a WordPress plugin used for managing events and selling tickets via WooCommerce. A security flaw allows an attacker to trick a website administrator into performing unintended actions, such as changing settings or deleting data, by clicking a malicious link. While this requires the administrator to be logged in and interact with the link, it could lead to unauthorized changes to the event management system.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Magepeople inc. WpEvently plugin (also known as Event Manager and Tickets Selling Plugin for WooCommerce) through version 4.1.2. The vulnerability stems from a lack of proper nonce validation on sensitive administrative functions. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a malicious link or hidden form). Successful exploitation allows the attacker to perform actions with the privileges of the victim user, though it does not directly allow for data theft (Confidentiality: None). The issue is resolved in version 4.1.3.

Affected products

  • Magepeople inc. WpEvently <= 4.1.2

Timeline

  • 2024-01-23: disclosed: Reported by Dhabaleshwar Das
  • 2024-04-11: advisory: Patchstack published advisory
  • 2024-04-11: patched: Fixed in version 4.1.3
  • 2026-06-11: other: NVD publication date

References

Related threats