PT-2024-37950 · WordPress · Eventon

Dk4Trin

·

Published

2024-09-08

·

Updated

2024-10-07

·

CVE-2024-6910

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EventON WordPress plugin versions prior to 2.2.17
Description The issue allows high privilege users, such as admins, to perform Cross-Site Scripting attacks by injecting malicious scripts, even when unfiltered html is disallowed. This is due to the plugin not sanitizing and escaping some of its settings.
Recommendations For versions prior to 2.2.17, upgrade the affected plugin immediately to protect your site. As a temporary workaround, consider restricting access to the plugin's settings handler to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6910

Affected Products

Eventon