PoC Index

CVE-2024-0237

MEDIUM 5.3EPSS 0.4%

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.41% chance of exploitation in the next 30 days, 34th percentile
Published
2024-01-16
Updated
2025-06-02

Proof-of-concept exploits (1)

References

Related