PoC Index

CVE-2024-0235

MEDIUM 5.3EPSS 38.0%

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
37.96% chance of exploitation in the next 30 days, 98th percentile
Nuclei
medium · CWE-862
Published
2024-01-16
Updated
2025-06-20

Proof-of-concept exploits (3)

Nuclei templates (1)

References

Related