CVE-2023-6005


EventON (Free < 2.2.7, Premium < 4.5.5) - Admin+ Stored Cross-Site Scripting

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).



We have discovered 13,983 live websites that are affected by CVE-2023-6005.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 4.5.5
Total Vulnerable Versions194
Vulnerable Domains13,983 live websites (84.34% of EventOn install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-6005 and the relative popularity of websites


Details

  • Published - Jan 16, 2024
  • Updated - Feb 5, 2024

Credits

  • Miguel Santareno (finder)
  • WPScan (coordinator)





Countries

United States4,470 websites



Germany1,382 websites
France1,107 websites
Spain709 websites
Italy691 websites
GB681 websites
Netherlands524 websites
Canada462 websites
Brazil298 websites
Australia288 websites

TLDs

.com4,887 websites
.org1,849 websites
.de964 websites
.fr468 websites
.it464 websites
.nl444 websites
.co.uk343 websites
.net276 websites
.es275 websites
.ch222 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-6005 through included software libraries and plugins.



References


Websites affected by CVE-2023-6005

Top websites that are affected by CVE-2023-6005. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*************.pl Poland**,***
*********************.org United States**,***
*****************.hr Croatia**,***
****.hr Croatia**,***
***.*******.org United States**,***
***.org United States**,***
***********.com United States**,***
*****.gov United States**,***
*******.com United States**,***
***.************.org United States**,***
See full domain list