The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:56:59.963Z
Updated: 2025-06-02T15:09:36.305Z
Reserved: 2024-01-04T14:28:08.685Z
Link: CVE-2024-0237

Updated: 2024-08-01T17:41:16.054Z

Status : Modified
Published: 2024-01-16T16:15:14.413
Modified: 2025-06-02T15:15:26.280
Link: CVE-2024-0237

No data.