Unknown Eventon vulnerabilities

13 known vulnerabilities affecting unknown/eventon.

Total CVEs
13
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
MEDIUM13

Vulnerabilities

Page 1 of 1
CVE-2024-6910MEDIUMCVSS 4.8fixed in 2.2.172024-09-09
CVE-2024-6910 [MEDIUM] CWE-79 CVE-2024-6910: The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
cvelistv5nvd
CVE-2024-4752MEDIUMCVSS 5.9fixed in 2.2.152024-07-13
CVE-2024-4752 [MEDIUM] CWE-79 CVE-2024-4752: The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2023-7200MEDIUMCVSS 6.1fixed in 4.4.12024-01-29
CVE-2023-7200 [MEDIUM] CWE-79 CVE-2023-7200: The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
cvelistv5nvd
CVE-2024-0238MEDIUMCVSS 6.1fixed in 2.2.82024-01-16
CVE-2024-0238 [MEDIUM] CWE-79 CVE-2024-0238: The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
cvelistv5nvd
CVE-2024-0236MEDIUMCVSS 5.3fixed in 4.5.5fixed in 2.2.72024-01-16
CVE-2024-0236 [MEDIUM] CWE-862 CVE-2024-0236: The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authori The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
cvelistv5nvd
CVE-2024-0233MEDIUMCVSS 6.1fixed in 4.5.5fixed in 2.2.72024-01-16
CVE-2024-0233 [MEDIUM] CWE-79 CVE-2024-0233: The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly san The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
cvelistv5nvd
CVE-2023-6046MEDIUMCVSS 4.8fixed in 2.22024-01-16
CVE-2023-6046 [MEDIUM] CWE-79 CVE-2023-6046: The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which cou The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.
cvelistv5nvd
CVE-2024-0235MEDIUMCVSS 5.3PoCfixed in 4.5.5fixed in 2.2.72024-01-16
CVE-2024-0235 [MEDIUM] CWE-862 CVE-2024-0235: The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authori The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
cvelistv5nvd
CVE-2023-6005MEDIUMCVSS 4.8fixed in 4.5.5fixed in 2.2.72024-01-16
CVE-2023-6005 [MEDIUM] CWE-79 CVE-2023-6005: The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize a The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd
CVE-2024-0237MEDIUMCVSS 5.3fixed in 2.2.72024-01-16
CVE-2024-0237 [MEDIUM] CWE-862 CVE-2024-0237: The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have author The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc
cvelistv5nvd
CVE-2023-4388MEDIUMCVSS 4.8fixed in 2.22023-10-16
CVE-2023-4388 [MEDIUM] CWE-79 CVE-2023-4388: The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which cou The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2023-2796MEDIUMCVSS 5.3PoCfixed in 2.1.22023-07-10
CVE-2023-2796 [MEDIUM] CWE-862 CVE-2023-2796: The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_ The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
cvelistv5nvd
CVE-2023-3219MEDIUMCVSS 5.3PoCfixed in 2.1.22023-07-10
CVE-2023-3219 [MEDIUM] CWE-639 CVE-2023-3219: The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its event The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
cvelistv5nvd