CVE-2024-0236
Published Jan 16, 2024
Last updated 10 months ago
Overview
- Description
- The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
- Source
- contact@wpscan.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- CWE-862
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "150D2D60-69AA-4027-AC89-D3929C2C5ECA", "versionEndExcluding": "2.2.7" }, { "criteria": "cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "57B6B80A-D3E7-4D93-B2BA-4A823879356F", "versionEndExcluding": "4.5.5", "versionStartIncluding": "4.0" } ], "operator": "OR" } ] } ]