Vulnerabilities (CVE)

Filtered by vendor Myeventon Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3219 1 Myeventon 1 Eventon 2023-08-04 N/A 5.3 MEDIUM
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
CVE-2023-2796 1 Myeventon 1 Eventon 2023-08-04 N/A 5.3 MEDIUM
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
CVE-2020-29395 1 Myeventon 1 Eventon 2020-12-01 4.3 MEDIUM 6.1 MEDIUM
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.