PT-2024-14909 · WordPress · The Eventon

Francesco Carlucci

·

Published

2024-01-11

·

Updated

2024-01-18

·

CVE-2023-6242

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The EventON - WordPress Virtual Event Calendar Plugin versions 2.2.7 and earlier (for Free) The EventON - WordPress Virtual Event Calendar Plugin versions 4.5.4 and earlier (for Pro)
Description The issue is due to missing or incorrect nonce validation on the evo eventpost update meta function, making it possible for unauthenticated attackers to update arbitrary post metadata via a forged request. This can happen if an attacker can trick a site administrator into performing an action such as clicking on a link.
Recommendations For versions 2.2.7 and earlier (for Free), update to a version later than 2.2.7 to resolve the issue. For versions 4.5.4 and earlier (for Pro), update to a version later than 4.5.4 to resolve the issue. As a temporary workaround, consider disabling the evo eventpost update meta function until a patch is available.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6242

Affected Products

The Eventon