CVE-2024-0235
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
El complemento EventON WordPress anterior a 4.5.5 y el complemento EventON WordPress anterior a 2.2.7 no tienen autorización en una acción AJAX, lo que permite a los usuarios no autenticados recuperar direcciones de correo electrónico de cualquier usuario en el blog.
The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_virtual_users() function in all versions up, and including to 4.5.4 (premium) & 2.2.7 (free). This makes it possible for unauthenticated attackers to retrieve email addresses from the blog.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-04 CVE Reserved
- 2024-01-10 CVE Published
- 2024-06-21 First Exploit
- 2024-08-01 CVE Updated
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/Cappricio-Securities/CVE-2024-0235 | 2024-06-21 | |
https://wpscan.com/vulnerability/e370b99a-f485-42bd-96a3-60432a15a4e9 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Myeventon Search vendor "Myeventon" | Eventon Search vendor "Myeventon" for product "Eventon" | < 2.2.7 Search vendor "Myeventon" for product "Eventon" and version " < 2.2.7" | wordpress |
Affected
| ||||||
Myeventon Search vendor "Myeventon" | Eventon Search vendor "Myeventon" for product "Eventon" | >= 4.0 < 4.5.5 Search vendor "Myeventon" for product "Eventon" and version " >= 4.0 < 4.5.5" | wordpress |
Affected
|