The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 6,330 live websites that are affected by CVE-2023-6005.
| Product | |
| Category | Appointment Scheduling |
| Vulnerable Domains | 6,330 live websites (48% of Eventon Premium install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 114 versions ( 73% of all versions) |
| 1,997 websites | |
| 784 websites | |
| 496 websites | |
| 309 websites | |
| 299 websites | |
| 262 websites | |
| 240 websites | |
| 167 websites | |
| 150 websites | |
| 119 websites |
| .com | 2,120 websites |
| .org | 780 websites |
| .de | 519 websites |
| .nl | 218 websites |
| .fr | 213 websites |
| .it | 189 websites |
| .es | 143 websites |
| .net | 133 websites |
| .co.uk | 133 websites |
| .ch | 124 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.pl | **,*** | ||
| *******.org | **,*** | ||
| ***********.com | **,*** | ||
| ***.org | **,*** | ||
| *******.org | **,*** | ||
| ****.com | **,*** | ||
| *****.**.il | **,*** | ||
| *******.**.ke | ***,*** | ||
| *****.org | ***,*** | ||
| **********.org | ***,*** |
FAQ