The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
We have discovered 10,791 live websites that are affected by CVE-2024-0236.
Product | |
Category | Appointment Scheduling |
Vulnerable Domains | 10,791 live websites (60.38% of EventOn install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 171 versions ( 87.69% of all versions) |
![]() | 4,128 websites |
![]() | 1,423 websites |
![]() | 915 websites |
![]() | 415 websites |
![]() | 399 websites |
![]() | 357 websites |
![]() | 288 websites |
![]() | 226 websites |
![]() | 178 websites |
![]() | 178 websites |
.com | 3,798 websites |
.org | 1,265 websites |
.de | 774 websites |
.nl | 370 websites |
.fr | 349 websites |
.it | 260 websites |
.co.uk | 247 websites |
.es | 226 websites |
.net | 213 websites |
.ch | 193 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********************.org | ![]() | **,*** | |
*****************.hr | ![]() | **,*** | |
****.hr | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
***.cat | ![]() | **,*** | |
****.com | ![]() | **,*** | |
*****************.fr | ![]() | ***,*** | |
*********************.org | ![]() | ***,*** | |
*******.**.ke | ![]() | ***,*** | |
**********.org | ![]() | ***,*** |
FAQ