CVE-2023-6005

EventON (Free < 2.2.7, Premium < 4.5.5) - Admin+ Stored Cross-Site Scripting

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 6,330 live websites that are affected by CVE-2023-6005.

Run a Free Instant Scan




Affected Software

Product  Eventon Premium
Category Appointment Scheduling
Vulnerable Domains6,330 live websites (48% of Eventon Premium install base)
Vulnerable Versions
  • from 0 through 4.5.5
Vulnerable Versions Count114 versions ( 73% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 16, 2024
  • Updated - Jun 20, 2025

Credits

  • Miguel Santareno (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-6005
United States1,997 websites



Germany784 websites
France496 websites
Spain309 websites
GB299 websites
Italy262 websites
Netherlands240 websites
Canada167 websites
Switzerland150 websites
Brazil119 websites

Website Distribution by TLD

Number of websites using CVE-2023-6005
.com2,120 websites
.org780 websites
.de519 websites
.nl218 websites
.fr213 websites
.it189 websites
.es143 websites
.net133 websites
.co.uk133 websites
.ch124 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6005

Top websites that are affected by CVE-2023-6005. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.pl Poland**,***
*******.org United States**,***
***********.com United States**,***
***.org France**,***
*******.org United States**,***
****.com GB**,***
*****.**.il Israel**,***
*******.**.ke Kenya***,***
*****.org United States***,***
**********.org France***,***
See full domain list

FAQ

CVE-2023-6005 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Eventon Premium
A total of 6,330 websites have been identified as vulnerable to CVE-2023-6005, based on global website indexing conducted by WebTechSurvey.
The Eventon Premium is affected by the CVE-2023-6005 vulnerability.
Eventon Premium versions up to 4.5.5 are vulnerable to CVE-2023-6005.
CVE-2023-6005 is resolved in version 4.5.5 of Eventon Premium.