CVE-2023-4388


EventON < 2.2 - Admin+ Stored XSS

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)



We have discovered 121 live websites that are affected by CVE-2023-4388.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 2.2
Total Vulnerable Versions194
Vulnerable Domains121 live websites (0.73% of EventOn install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-4388 and the relative popularity of websites


Details

  • Published - Oct 16, 2023
  • Updated - Oct 16, 2023

Credits

  • Miguel Santareno (finder)
  • WPScan (coordinator)





Countries

United States30 websites



Italy15 websites
France12 websites
Germany11 websites
Netherlands7 websites
Spain6 websites
Chile5 websites
GB4 websites
Austria3 websites
Hungary3 websites

TLDs

.com48 websites
.de8 websites
.fr8 websites
.nl7 websites
.it7 websites
.org4 websites
.co.uk3 websites
.net3 websites
.es3 websites
.at2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-4388 through included software libraries and plugins.



References


Websites affected by CVE-2023-4388

Top websites that are affected by CVE-2023-4388. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.hu Hungary**,***
***.*********.cl Chile***,***
*****.it Italy*,***,***
****.**********.com United States*,***,***
***.************.com France*,***,***
***.*******.at Austria*,***,***
***.***********.cl Chile*,***,***
***.***********.fr France*,***,***
***************.de Germany*,***,***
************************.at Austria*,***,***
See full domain list