CVE-2023-2796


EventON < 2.1.2 - Unauthenticated Event Access

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.



We have discovered 61 live websites that are affected by CVE-2023-2796.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 2.1.2
Total Vulnerable Versions194
Vulnerable Domains61 live websites (0.37% of EventOn install base)


Common Weakness Enumeration


CWE-862 Missing Authorization


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-2796 and the relative popularity of websites


Details

  • Published - Jul 10, 2023
  • Updated - Jul 10, 2023

Credits

  • Miguel Santareno (finder)
  • WPScan (coordinator)





Countries

United States16 websites



France11 websites
Germany7 websites
Spain5 websites
Italy4 websites
Austria3 websites
Netherlands3 websites
Bulgaria1 websites
Switzerland1 websites
Chile1 websites

TLDs

.com24 websites
.fr8 websites
.de6 websites
.es3 websites
.nl3 websites
.at2 websites
.it2 websites
.net2 websites
.cz1 websites
.eu1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-2796 through included software libraries and plugins.



References


Websites affected by CVE-2023-2796

Top websites that are affected by CVE-2023-2796. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.hu Hungary**,***
****.**********.com United States*,***,***
***.*******.at Austria*,***,***
***.***********.cl Chile*,***,***
***.***********.fr France*,***,***
***************.de Germany*,***,***
************************.at Austria*,***,***
***.*****************.it Italy*,***,***
***.*************.fr France*,***,***
*****.fr France*,***,***
See full domain list