CVE-2023-6244




The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation on the save_virtual_event_settings function. This makes it possible for unauthenticated attackers to modify virtual event settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.



We have discovered 226 live websites that are affected by CVE-2023-6244.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 through 2.2.8
Total Vulnerable Versions194
Vulnerable Domains226 live websites (1.36% of EventOn install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-6244 and the relative popularity of websites


Details

  • Published - Jan 11, 2024
  • Updated - Jan 11, 2024

Credits

  • Francesco Carlucci (finder)




Countries

United States52 websites



France27 websites
Italy23 websites
Germany19 websites
Spain12 websites
Netherlands11 websites
GB8 websites
Chile7 websites
Austria6 websites
Poland6 websites

TLDs

.com92 websites
.fr13 websites
.de13 websites
.it11 websites
.nl11 websites
.org10 websites
.es6 websites
.ru5 websites
.co.uk4 websites
.net4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-6244 through included software libraries and plugins.



References


Websites affected by CVE-2023-6244

Top websites that are affected by CVE-2023-6244. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.hu Hungary**,***
***.*********.cl Chile***,***
*******.com United States***,***
***************************.es Spain*,***,***
*****.it Italy*,***,***
************.com United States*,***,***
***.*************.org United States*,***,***
***.********.com France*,***,***
****.**********.com United States*,***,***
***.************.com France*,***,***
See full domain list