The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:57:04.379Z

Updated: 2024-02-05T21:23:06.278Z

Reserved: 2024-01-04T13:18:40.886Z


Link: CVE-2024-0235

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-16T16:15:14.327

Modified: 2024-01-19T14:28:22.047


Link: CVE-2024-0235

JSON object: View

cve-icon Redhat Information

No data.

CWE