Extension WordPress
Vulnérabilités EventON – Events Calendar
Cette page rassemble les failles publiées pour EventON – Events Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de EventON – Events Calendar
21 fiches
EventON Lite <= 2.4.7 – Authenticated (Contributor+) Information Disclosure
The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes…
*-2.4.7
2.4.8
14/08/2025
EventON <= 2.4.4 – Missing Authorization
The EventON – Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to…
*-2.4.4
2.4.5
16/05/2025
EventON <= 2.4.1 – Authenticated (Contributor+) Local File Inclusion
The EventON plugin for WordPress is vulnerable to Local File Inclusion via the evo_block_render_callback() function in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute…
*-2.4.1
2.4.2
07/05/2025
EventON <= 2.4 – Unauthenticated Local File Inclusion
The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
*-2.4
2.4.1
09/04/2025
EventON <= 2.4.1 – Authenticated (Contributor+) Local File Inclusion
The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-2.4.1
2.4.2
04/04/2025
EventON <= 2.2.16 – Authenticated (Admin+) Stored Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.2.16
2.2.17
19/08/2024
EventON <= 2.2.15 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates
The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers…
*-2.2.15
2.2.16
08/07/2024
EventON <= 2.2.14 – Authenticated (Administrator+) Stored Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.2.14
2.2.15
30/04/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.8 (Pro) & <= 2.2.7 (Free) – Missing Authorization via eventon_save_virtual_event_settings
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on several function in various versions. This makes it possible for unauthenticated attackers to save virtual event settings.
*-2.2.7
2.2.8
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Authenticated (Admin+) Stored Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible…
*-2.2.7
2.2.8
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Reflected Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it…
*-2.2.7
2.2.8
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Missing Authorization via get_virtual_users
The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_virtual_users() function in all versions up, and including to 4.5.4 (premium) & 2.2.7 (free). This makes it possible…
*-2.2.7
2.2.8
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Missing Authorization via config_virtual_event
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the config_virtual_event() function in various versions. This makes it possible for unauthenticated attackers to retrieve the settings of…
*-2.2.7
2.2.8
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 – Cross-Site Request Forgery via evo_eventpost_update_meta
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect…
*-2.2.7
2.2.8
09/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) – Cross-Site Request Forgery via save_virtual_event_settings
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation…
*-2.2.8
2.2.9
09/01/2024
EventON – WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 – Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and…
*-2.2.7
2.2.8
09/01/2024
EventON <= 2.1.7 – Authenticated (Admin+) HTML Injection
The EventON plugin for WordPress is vulnerable to HTML Injection via admin settings in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-2.1.7
2.2
09/11/2023
EventON <= 2.2.2 – Reflected Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.2.2
2.2.3
20/10/2023
EventON <= 2.1.7 – Authenticated (Admin+) Stored Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.1.7
2.2
21/09/2023
EventON <= 2.1 – Missing Authorization to Event Access
The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the eventon_ics_download function in versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to view…
*-2.1
2.1.2
19/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.