CVE-2024-0236

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:46

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - Third Party Advisory () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - Third Party Advisory

19 Jan 2024, 14:28

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
First Time Myeventon eventon
Myeventon
CWE CWE-862
References () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - Third Party Advisory

16 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 16:15

Updated : 2024-11-21 08:46


NVD link : CVE-2024-0236

Mitre link : CVE-2024-0236

CVE.ORG link : CVE-2024-0236


JSON object : View

Products Affected

myeventon

  • eventon
CWE
CWE-862

Missing Authorization