CVE-2024-29776 MEDIUM

CVE-2024-29776: WordPress EventPrime plugin <= 3.3.9 - Cross Site Scripting (XSS) vulnerability

Vendor Metagauss
Product EventPrime
Published March 27, 2024
Last update April 28, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

Explanation of Vulnerability in Simple Terms

02Summary

EventPrime versions up to 3.3.9 contain a vulnerability that allows authenticated administrators with high privileges to perform actions affecting confidentiality, integrity, and availability when a user interacts with a malicious link or page. The vulnerability has limited scope but requires both admin-level access and user interaction to exploit.

What an attacker can do

03Attacker Capabilities

An authenticated admin can leak sensitive data, modify site content, or degrade performance when a user clicks a malicious link.

Potential impact on your site

04Site Impact

If an admin account is compromised or an admin is socially engineered, site data and functionality could be affected.

Conditions required to exploit

05Prerequisites

Attacker must have admin-level access to EventPrime and trick a user into clicking a link or visiting a page.

Key dates

06Disclosure timeline

March 27, 2024 CVE published
April 28, 2026 Record updated