CVE-2024-0236

EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Virtual Event Password Disclosure

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)


We have discovered 10,791 live websites that are affected by CVE-2024-0236.

Test my site




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Domains10,791 live websites (60.38% of EventOn install base)
Vulnerable Versions
  • from 0 before 4.5.5
Vulnerable Versions Count171 versions ( 87.69% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 16, 2024
  • Updated - Aug 1, 2024

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)

CVE-2024-0236 usage by Country

United States4,128 websites



Germany1,423 websites
France915 websites
Spain415 websites
GB399 websites
Netherlands357 websites
Italy288 websites
Switzerland226 websites
Brazil178 websites
Canada178 websites

CVE-2024-0236 usage by TLD

.com3,798 websites
.org1,265 websites
.de774 websites
.nl370 websites
.fr349 websites
.it260 websites
.co.uk247 websites
.es226 websites
.net213 websites
.ch193 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-0236

Top websites that are affected by CVE-2024-0236. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.org United States**,***
*****************.hr Croatia**,***
****.hr Croatia**,***
***********.com United States**,***
***.cat Germany**,***
****.com United States**,***
*****************.fr France***,***
*********************.org Germany***,***
*******.**.ke Kenya***,***
**********.org France***,***
See full domain list

FAQ

CVE-2024-0236 is Missing Authorization in EventOn
A total of 10,791 websites have been identified as vulnerable to CVE-2024-0236, discovered through global website indexing conducted by WebTechSurvey.
EventOn is susceptible to CVE-2024-0236 vulnerability.
EventOn versions before 4.5.5 are vulnerable to CVE-2024-0236.
Version 4.5.5 of EventOn addresses the CVE-2024-0236 security vulnerability.