CVE-2023-6005

EventON (Free < 2.2.7, Premium < 4.5.5) - Admin+ Stored Cross-Site Scripting

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 10,791 live websites that are affected by CVE-2023-6005.

Test my site




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Domains10,791 live websites (60.38% of EventOn install base)
Vulnerable Versions
  • from 0 before 4.5.5
Vulnerable Versions Count171 versions ( 87.69% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 16, 2024
  • Updated - Aug 2, 2024

Credits

  • Miguel Santareno (finder)
  • WPScan (coordinator)

CVE-2023-6005 usage by Country

United States4,128 websites



Germany1,423 websites
France915 websites
Spain415 websites
GB399 websites
Netherlands357 websites
Italy288 websites
Switzerland226 websites
Brazil178 websites
Canada178 websites

CVE-2023-6005 usage by TLD

.com3,798 websites
.org1,265 websites
.de774 websites
.nl370 websites
.fr349 websites
.it260 websites
.co.uk247 websites
.es226 websites
.net213 websites
.ch193 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6005

Top websites that are affected by CVE-2023-6005. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.org United States**,***
*****************.hr Croatia**,***
****.hr Croatia**,***
***********.com United States**,***
***.cat Germany**,***
****.com United States**,***
*****************.fr France***,***
*********************.org Germany***,***
*******.**.ke Kenya***,***
**********.org France***,***
See full domain list

FAQ

CVE-2023-6005 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EventOn
A total of 10,791 websites have been identified as vulnerable to CVE-2023-6005, discovered through global website indexing conducted by WebTechSurvey.
EventOn is susceptible to CVE-2023-6005 vulnerability.
EventOn versions before 4.5.5 are vulnerable to CVE-2023-6005.
Version 4.5.5 of EventOn addresses the CVE-2023-6005 security vulnerability.