Showing 4 vulnerabilities on this page for eventon

Signals CISA KEV Ransomware Nuclei
myeventon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

EventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitle

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CWE-79Jul 13, 2024
CVSS5.9v3.1EPSS0.398%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers to update plugin settings, including adding stored cross-site scripting to settings options displayed on event calendar pages.

CWE-862Jul 9, 2024
CVSS7.2v3.1EPSS0.457%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

CWE-862Jan 16, 20241 related artifact
CVSS5.3v3.1EPSS38%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

EventON < 2.1.2 - Unauthenticated Event Access

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

CWE-862Jul 10, 20231 related artifact
CVSS5.3v3.1EPSS42.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX