PT-2024-14911 · WordPress · Eventon

Francesco Carlucci

·

Published

2024-01-11

·

Updated

2024-01-18

·

CVE-2023-6244

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The EventON - WordPress Virtual Event Calendar Plugin versions up to, and including, 4.5.4 (Pro) and 2.2.8 (Free)
Description The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the save virtual event settings function. This allows unauthenticated attackers to modify virtual event settings via a forged request if they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 4.5.4 (Pro) and 2.2.8 (Free), consider disabling the save virtual event settings function until a patch is available to prevent exploitation. Restrict access to virtual event settings to minimize the risk of unauthorized modifications. Avoid performing actions that could be triggered by forged requests, such as clicking on suspicious links, to prevent potential attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-6244

Affected Products

Eventon