CVE-2023-4635




The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.



We have discovered 135 live websites that are affected by CVE-2023-4635.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 through 2.2.2
Total Vulnerable Versions194
Vulnerable Domains135 live websites (0.81% of EventOn install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-4635 and the relative popularity of websites


Details

  • Published - Oct 21, 2023
  • Updated - Oct 21, 2023

Credits

  • Shuning Xu (finder)




Countries

United States33 websites



France15 websites
Italy15 websites
Germany12 websites
Netherlands7 websites
Spain6 websites
GB5 websites
Chile5 websites
Austria3 websites
Hungary3 websites

TLDs

.com52 websites
.de9 websites
.fr9 websites
.nl7 websites
.it7 websites
.org5 websites
.co.uk4 websites
.net3 websites
.es3 websites
.at2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-4635 through included software libraries and plugins.



References


Websites affected by CVE-2023-4635

Top websites that are affected by CVE-2023-4635. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.hu Hungary**,***
***.*********.cl Chile***,***
*******.com United States***,***
*****.it Italy*,***,***
***.********.com France*,***,***
****.**********.com United States*,***,***
***.************.com France*,***,***
***.*******.at Austria*,***,***
***.***********.cl Chile*,***,***
***.***********.fr France*,***,***
See full domain list