CVE-2023-6158




The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possible for unauthenticated attackers to update and remove arbitrary post metadata. Note that certain parameters may allow for content injection.



We have discovered 217 live websites that are affected by CVE-2023-6158.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 through 2.2.7
Total Vulnerable Versions194
Vulnerable Domains217 live websites (1.31% of EventOn install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-6158 and the relative popularity of websites


Details

  • Published - Jan 10, 2024
  • Updated - Jan 10, 2024

Credits

  • Francesco Carlucci (finder)




Countries

United States51 websites



France24 websites
Italy21 websites
Germany19 websites
Spain12 websites
Netherlands11 websites
GB8 websites
Chile7 websites
Poland6 websites
Hungary5 websites

TLDs

.com86 websites
.fr13 websites
.de13 websites
.nl11 websites
.org10 websites
.it10 websites
.es6 websites
.ru5 websites
.co.uk4 websites
.net4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-6158 through included software libraries and plugins.



References


Websites affected by CVE-2023-6158

Top websites that are affected by CVE-2023-6158. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.hu Hungary**,***
***.*********.cl Chile***,***
*******.com United States***,***
***************************.es Spain*,***,***
*****.it Italy*,***,***
************.com United States*,***,***
***.*************.org United States*,***,***
***.********.com France*,***,***
****.**********.com United States*,***,***
***.************.com France*,***,***
See full domain list