CVE-2020-29395
MEDIUMNuclei
Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
Record summary
CVE-2020-29395 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site ScriptingExploitDB exploitby B3KC4TNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordpress EventON Calendar 3.0.5 - Cross-Site ScriptingCVSS 6.1
Wordpress EventON Calendar 3.0.5 is vulnerable to cross-site scripting because it allows addons/?q= XSS via the search field.
Impact
Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.
Remediation
Update to the latest version of the Wordpress EventON Calendar plugin (3.0.6) to mitigate this vulnerability.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2020wordpressxsswp-pluginpacketstormmyeventonvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/eventon/
Shodan: http.html:/wp-content/plugins/eventon-lite/
FOFA: wp-content/plugins/eventon/
FOFA: body=/wp-content/plugins/eventon/
FOFA: body=/wp-content/plugins/eventon-lite/
Google: inurl:"/wp-content/plugins/eventon/"
https://github.com/mustgundogdu/Research/tree/main/EventON_PLUGIN_XSS https://www.myeventon.com/news/ https://nvd.nist.gov/vuln/detail/CVE-2020-29395 http://packetstormsecurity.com/files/160282/WordPress-EventON-Calendar-3.0.5-Cross-Site-Scripting.html https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/160282/WordPress-EventON-Calendar-3.0.5-Cross-Site-Scripting.html github.com
https://github.com/mustgundogdu/Research/tree/main/EventON_PLUGIN_XSS nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-29395 myeventon.com
https://www.myeventon.com/news