CyberRota Analysis
AI-GeneratedThe Eventin WordPress plugin prior to version 4.1.20 has a vulnerability that permits users with contributor-level access and higher to access and read other customers' order records, which may include sensitive personal information. This flaw arises from inadequate access controls, enabling unauthorized data exposure through order identifier enumeration. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers.