CVE-2025-47564

WordPress EventON plugin <= 4.9.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in ashanjay EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 4.9.9.


We have discovered 15,075 live websites that are affected by CVE-2025-47564.

Run a Free Instant Scan




Affected Software

Product  Eventon Premium
Category Appointment Scheduling
Vulnerable Domains15,075 live websites (99.87% of Eventon Premium install base)
Vulnerable Versions
  • from 0 through 4.9.9
Vulnerable Versions Count149 versions ( 99.33% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - May 16, 2025
  • Updated - May 16, 2025

Credits

  • Anhchangmutrang (Patchstack Alliance) (finder)

CVE-2025-47564 usage by Country

United States6,042 websites



Germany2,305 websites
France1,076 websites
GB546 websites
Netherlands544 websites
Spain512 websites
Italy481 websites
Switzerland426 websites
Denmark254 websites
Canada215 websites

CVE-2025-47564 usage by TLD

.com4,981 websites
.org2,048 websites
.de1,434 websites
.nl593 websites
.fr441 websites
.it394 websites
.ch354 websites
.co.uk337 websites
.es301 websites
.net272 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-47564

Top websites that are affected by CVE-2025-47564. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.pl Czech Republic**,***
*****************.hr Croatia**,***
*****.com United States**,***
****.hr Croatia**,***
**************.org United States**,***
***.com United States**,***
*****.com United States**,***
****************.net United States**,***
***********.com United States**,***
*******.com United States**,***
See full domain list

FAQ

CVE-2025-47564 is Missing Authorization in Eventon Premium
A total of 15,075 websites have been identified as vulnerable to CVE-2025-47564, based on global website indexing conducted by WebTechSurvey.
The Eventon Premium is affected by the CVE-2025-47564 vulnerability.
Eventon Premium versions up to and including 4.9.9 are vulnerable to CVE-2025-47564.