CVE-2024-0235


EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog



We have discovered 13,983 live websites that are affected by CVE-2024-0235.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 4.5.5
Total Vulnerable Versions194
Vulnerable Domains13,983 live websites (84.34% of EventOn install base)


Common Weakness Enumeration


CWE-862 Missing Authorization


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-0235 and the relative popularity of websites


Details

  • Published - Jan 16, 2024
  • Updated - Feb 5, 2024

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States4,470 websites



Germany1,382 websites
France1,107 websites
Spain709 websites
Italy691 websites
GB681 websites
Netherlands524 websites
Canada462 websites
Brazil298 websites
Australia288 websites

TLDs

.com4,887 websites
.org1,849 websites
.de964 websites
.fr468 websites
.it464 websites
.nl444 websites
.co.uk343 websites
.net276 websites
.es275 websites
.ch222 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-0235 through included software libraries and plugins.



References


Websites affected by CVE-2024-0235

Top websites that are affected by CVE-2024-0235. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*************.pl Poland**,***
*********************.org United States**,***
*****************.hr Croatia**,***
****.hr Croatia**,***
***.*******.org United States**,***
***.org United States**,***
***********.com United States**,***
*****.gov United States**,***
*******.com United States**,***
***.************.org United States**,***
See full domain list