Record summary

CVE-2020-29395 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site ScriptingExploitDB exploitby B3KC4TNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordpress EventON Calendar 3.0.5 - Cross-Site ScriptingCVSS 6.1

Wordpress EventON Calendar 3.0.5 is vulnerable to cross-site scripting because it allows addons/?q= XSS via the search field.

Impact

Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.

Remediation

Update to the latest version of the Wordpress EventON Calendar plugin (3.0.6) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2020wordpressxsswp-pluginpacketstormmyeventonvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/eventon/
Shodan: http.html:/wp-content/plugins/eventon-lite/
FOFA: wp-content/plugins/eventon/
FOFA: body=/wp-content/plugins/eventon/
FOFA: body=/wp-content/plugins/eventon-lite/
Google: inurl:"/wp-content/plugins/eventon/"

Source: ProjectDiscovery

References

4