CVE-2024-0235
MEDIUM 5.3EPSS 38.0%
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS
- 37.96% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- medium · CWE-862
- Published
- 2024-01-16
- Updated
- 2025-06-20
Proof-of-concept exploits (3)
- https://wpscan.com/vulnerability/e370b99a-f485-42bd-96a3-60432a15a4e9/
- Cappricio-Securities/CVE-2024-02350★ · 2024-06-24
- Nxploited/CVE-2024-0235-PoC0★ · 2025-01-30