Vulnerability CVE-2023-2796


Published: 2023-07-10

Description:
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
WordPress EventON Calendar 4.4 Insecure Direct Object Reference
Miguel Santareno
06.08.2023

Type:

CWE-862

(Missing Authorization)

 References:
https://wpscan.com/vulnerability/e9ef793c-e5a3-4c55-beee-56b0909f7a0d

Copyright 2024, cxsecurity.com

 

Back to Top