CVE-2024-0238

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*

History

05 Feb 2024, 22:15

Type Values Removed Values Added
Summary (en) The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata. (en) The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

19 Jan 2024, 14:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
CWE-862
References () https://wpscan.com/vulnerability/774655ac-b201-4d9f-8790-9eff8564bc91/ - () https://wpscan.com/vulnerability/774655ac-b201-4d9f-8790-9eff8564bc91/ - Third Party Advisory
Summary
  • (es) El complemento EventON WordPress anterior a 4.5.5 y el complemento EventON WordPress anterior a 2.2.7 no tienen autorización en una acción AJAX y no garantizan que la publicación que se actualizará pertenezca al complemento, lo que permite a usuarios no autenticados actualizar metadatos de publicaciones arbitrarias.
First Time Myeventon
Myeventon eventon
CPE cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*

16 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 16:15

Updated : 2024-02-05 22:15


NVD link : CVE-2024-0238

Mitre link : CVE-2024-0238

CVE.ORG link : CVE-2024-0238


JSON object : View

Products Affected

myeventon

  • eventon
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-862

Missing Authorization