CVE-2024-0236
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Virtual Event Password Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
El complemento EventON WordPress anterior a 4.5.5 y el complemento EventON WordPress anterior a 2.2.7 no tienen autorización en una acción AJAX, lo que permite a usuarios no autenticados recuperar la configuración de eventos virtuales arbitrarios, incluida cualquier contraseña de reunión establecida (por ejemplo, para Zoom).
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the config_virtual_event() function in various versions. This makes it possible for unauthenticated attackers to retrieve the settings of arbitrary virtual events which can contain password data.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-04 CVE Reserved
- 2024-01-10 CVE Published
- 2024-01-24 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Myeventon Search vendor "Myeventon" | Eventon Search vendor "Myeventon" for product "Eventon" | < 2.2.7 Search vendor "Myeventon" for product "Eventon" and version " < 2.2.7" | wordpress |
Affected
| ||||||
Myeventon Search vendor "Myeventon" | Eventon Search vendor "Myeventon" for product "Eventon" | >= 4.0 < 4.5.5 Search vendor "Myeventon" for product "Eventon" and version " >= 4.0 < 4.5.5" | wordpress |
Affected
|