CVE-2025-48116

WordPress EventON <= 2.4.4 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Ashan Perera EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 2.4.4.


We have discovered 2,913 live websites that are affected by CVE-2025-48116.

Run a Free Instant Scan




Affected Software

Product  Eventon Lite
Category Wordpress Plugins
Vulnerable Domains2,913 live websites (31.46% of Eventon Lite install base)
Vulnerable Versions
  • from 0 through 2.4.4
Vulnerable Versions Count68 versions ( 59.13% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - May 16, 2025
  • Updated - May 16, 2025

Credits

  • astra.r3verii (Patchstack Alliance) (finder)

CVE-2025-48116 usage by Country

United States920 websites



Germany483 websites
France296 websites
Italy136 websites
Netherlands113 websites
GB104 websites
Spain86 websites
Switzerland59 websites
Denmark52 websites
Canada48 websites

CVE-2025-48116 usage by TLD

.com901 websites
.org324 websites
.de320 websites
.fr122 websites
.nl117 websites
.it108 websites
.co.uk71 websites
.ch51 websites
.net48 websites
.com.br44 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-48116

Top websites that are affected by CVE-2025-48116. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.org United States**,***
*******.org United States**,***
*********.org United States**,***
********.com United States**,***
************.hu Hungary**,***
*******.com United States***,***
********************.ca United States***,***
********************.***.mx United States***,***
****************.in Cyprus***,***
********.com United States***,***
See full domain list

FAQ

CVE-2025-48116 is Missing Authorization in Eventon Lite
A total of 2,913 websites have been identified as vulnerable to CVE-2025-48116, based on global website indexing conducted by WebTechSurvey.
The Eventon Lite is affected by the CVE-2025-48116 vulnerability.
Eventon Lite versions up to and including 2.4.4 are vulnerable to CVE-2025-48116.