EventON < 2.1.2 - Unauthenticated Event Access
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 43%
from disclosure to weapon25 days
Published on NVDJul 10
1st PoC+25d
VulnCheck+196d
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
Affected products
Unknown · EventONpublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/51658unverifiedcve_referencepacketstormsecurity.com/files/173984/WordPress-EventON-Calendar-4.4-Insecure-Direct-Object-Reference.htmlunverifiedcve_referencewpscan.com/vulnerability/e9ef793c-e5a3-4c55-beee-56b0909f7a0dunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.