Home/Product/myeventon eventon
Product

myeventon eventon

20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-3527
<= 4.9.6
The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the '
6.4MEDIUM
CVE-2023-6243
< 4.7
The EventON PRO - WordPress Virtual Event Calendar Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all
4.3MEDIUM
CVE-2024-6910
< 2.2.17
The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege use
4.8MEDIUM
CVE-2024-4752
< 2.2.15
The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege use
5.9MEDIUM
CVE-2023-7200
< 4.4.1
The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading
6.1MEDIUM
CVE-2024-0238
< 2.2.7
The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX acti
6.1MEDIUM
CVE-2024-0237
< 2.2.7
The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions,
5.3MEDIUM
CVE-2024-0236
< 2.2.7
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allo
5.3MEDIUM
CVE-2024-0235
< 2.2.7
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allo
5.3MEDIUM
CVE-2024-0233
< 2.2.7
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter b
6.1MEDIUM
CVE-2023-6046
< 2.2
The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users
4.8MEDIUM
CVE-2023-6005
< 2.2.7
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings
4.8MEDIUM
CVE-2023-6244
< 2.2.9
The EventON - WordPress Virtual Event Calendar Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
6.5MEDIUM
CVE-2023-6242
< 2.2.8
The EventON - WordPress Virtual Event Calendar Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
6.5MEDIUM
CVE-2023-6158
<= 2.2.7
The EventON - WordPress Virtual Event Calendar Plugin for WordPress is vulnerable to unauthorized modification of data and
6.5MEDIUM
CVE-2023-4635
<= 2.2.2
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and in
6.1MEDIUM
CVE-2023-4388
< 2.2
The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users
4.8MEDIUM
CVE-2023-3219
< 2.1.2
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is
5.3MEDIUM
CVE-2023-2796
< 2.1.2
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing
5.3MEDIUM
CVE-2020-29395
<= 3.0.5
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
6.1MEDIUM
threatengine.sh