← back
CVE-2023-2796observed exploitation

EventON < 2.1.2 - Unauthenticated Event Access

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 43%
from disclosure to weapon25 days
Published on NVDJul 10
1st PoC+25d
VulnCheck+196d
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
Affected products
Unknown · EventON
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.