PT-2024-14892 · WordPress · The Eventon

Francesco Carlucci

·

Published

2024-01-10

·

Updated

2024-01-17

·

CVE-2023-6158

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions The EventON - WordPress Virtual Event Calendar Plugin versions 2.2.7 and earlier (for free) The EventON - WordPress Virtual Event Calendar Plugin versions 4.5.4 and earlier (for Pro)
Description The issue is related to a missing capability check on the evo eventpost update meta function, allowing unauthenticated attackers to update and remove arbitrary post metadata. This could potentially lead to unauthorized modification of data and loss of data. Certain parameters may also allow for content injection.
Recommendations For versions 2.2.7 and earlier (for free), update to a version later than 2.2.7 to resolve the issue. For versions 4.5.4 and earlier (for Pro), update to a version later than 4.5.4 to resolve the issue. As a temporary workaround, consider restricting access to the evo eventpost update meta function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6158

Affected Products

The Eventon