CVE-2024-0237

Severity
5.3MEDIUM
EPSS
0.3%
top 47.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5unknown/eventon< 2.2.7
NVDmyeventon/eventon4.04.5.5+1
CVEListV5unknown/eventon_premium< 4.5.8

🔴Vulnerability Details

2
GHSA
GHSA-c35g-g4wj-g2qg: The EventON WordPress plugin before 42024-01-16
CVEList
EventON (Free < 2.2.9, Premium <= 4.5.8) - Unauthenticated Virtual Event Settings Update2024-01-16
CVE-2024-0237 (MEDIUM CVSS 5.3) | The EventON WordPress plugin throug | cvebase.io