The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:57:05.090Z

Updated: 2024-02-05T21:23:07.225Z

Reserved: 2024-01-04T14:47:37.931Z


Link: CVE-2024-0238

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2024-01-16T16:15:14.467

Modified: 2024-02-05T22:15:59.563


Link: CVE-2024-0238

JSON object: View

cve-icon Redhat Information

No data.