PT-2024-14892 · WordPress · The Eventon
Francesco Carlucci
·
Published
2024-01-10
·
Updated
2024-01-17
·
CVE-2023-6158
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
The EventON - WordPress Virtual Event Calendar Plugin versions 2.2.7 and earlier (for free)
The EventON - WordPress Virtual Event Calendar Plugin versions 4.5.4 and earlier (for Pro)
Description
The issue is related to a missing capability check on the
evo eventpost update meta function, allowing unauthenticated attackers to update and remove arbitrary post metadata. This could potentially lead to unauthorized modification of data and loss of data. Certain parameters may also allow for content injection.Recommendations
For versions 2.2.7 and earlier (for free), update to a version later than 2.2.7 to resolve the issue.
For versions 4.5.4 and earlier (for Pro), update to a version later than 4.5.4 to resolve the issue.
As a temporary workaround, consider restricting access to the
evo eventpost update meta function until a patch is available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Eventon