The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 10,791 live websites that are affected by CVE-2023-6005.
Product | |
Category | Appointment Scheduling |
Vulnerable Domains | 10,791 live websites (60.38% of EventOn install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 171 versions ( 87.69% of all versions) |
![]() | 4,128 websites |
![]() | 1,423 websites |
![]() | 915 websites |
![]() | 415 websites |
![]() | 399 websites |
![]() | 357 websites |
![]() | 288 websites |
![]() | 226 websites |
![]() | 178 websites |
![]() | 178 websites |
.com | 3,798 websites |
.org | 1,265 websites |
.de | 774 websites |
.nl | 370 websites |
.fr | 349 websites |
.it | 260 websites |
.co.uk | 247 websites |
.es | 226 websites |
.net | 213 websites |
.ch | 193 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********************.org | ![]() | **,*** | |
*****************.hr | ![]() | **,*** | |
****.hr | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
***.cat | ![]() | **,*** | |
****.com | ![]() | **,*** | |
*****************.fr | ![]() | ***,*** | |
*********************.org | ![]() | ***,*** | |
*******.**.ke | ![]() | ***,*** | |
**********.org | ![]() | ***,*** |
FAQ