CVE-2024-0236

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*

History

19 Jan 2024, 14:28

Type Values Removed Values Added
CWE CWE-862
First Time Myeventon eventon
Myeventon
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - Third Party Advisory
CPE cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*

16 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 16:15

Updated : 2025-06-20 18:15


NVD link : CVE-2024-0236

Mitre link : CVE-2024-0236


JSON object : View

Products Affected

myeventon

  • eventon
CWE
CWE-862

Missing Authorization