The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:57:00.337Z

Updated: 2024-02-05T21:23:02.604Z

Reserved: 2024-01-04T14:13:27.704Z


Link: CVE-2024-0236

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-16T16:15:14.367

Modified: 2024-01-19T14:28:41.540


Link: CVE-2024-0236

JSON object: View

cve-icon Redhat Information

No data.

CWE