VulnerabilityModified
CVE-2024-0235
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
MEDIUM 5.3EPSS 38.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 37.96% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- myeventon/eventon
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/e370b99a-f485-42bd-96a3-60432a15a4e9/Third Party Advisory
- https://wpscan.com/vulnerability/e370b99a-f485-42bd-96a3-60432a15a4e9/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.