CVE-2024-0233


EventON (Free < 2.2.8, Premium < 4.5.5) - Reflected XSS

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin



We have discovered 13,983 live websites that are affected by CVE-2024-0233.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 4.5.5
Total Vulnerable Versions194
Vulnerable Domains13,983 live websites (84.34% of EventOn install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-0233 and the relative popularity of websites


Details

  • Published - Jan 16, 2024
  • Updated - Feb 5, 2024

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States4,470 websites



Germany1,382 websites
France1,107 websites
Spain709 websites
Italy691 websites
GB681 websites
Netherlands524 websites
Canada462 websites
Brazil298 websites
Australia288 websites

TLDs

.com4,887 websites
.org1,849 websites
.de964 websites
.fr468 websites
.it464 websites
.nl444 websites
.co.uk343 websites
.net276 websites
.es275 websites
.ch222 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-0233 through included software libraries and plugins.



References


Websites affected by CVE-2024-0233

Top websites that are affected by CVE-2024-0233. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*************.pl Poland**,***
*********************.org United States**,***
*****************.hr Croatia**,***
****.hr Croatia**,***
***.*******.org United States**,***
***.org United States**,***
***********.com United States**,***
*****.gov United States**,***
*******.com United States**,***
***.************.org United States**,***
See full domain list