PT-2024-15401 · WordPress · Eventon

Erwan Lr

·

Published

2024-01-16

·

Updated

2024-01-19

·

CVE-2024-0235

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions EventON WordPress plugin versions prior to 4.5.5 EventON WordPress plugin versions prior to 2.2.7
Description The issue allows unauthenticated users to retrieve email addresses of any users on the blog due to a lack of authorization in an AJAX action.
Recommendations For EventON WordPress plugin versions prior to 4.5.5, update to version 4.5.5 or later. For EventON WordPress plugin versions prior to 2.2.7, update to version 2.2.7 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0235

Affected Products

Eventon