Extension WordPress

Vulnérabilités EventON – Events Calendar

Cette page rassemble les failles publiées pour EventON – Events Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.

21Vulnérabilités
1Critiques
21Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de EventON – Events Calendar

21 fiches

CVE-2025-47494 Élevée · 8,8
EventON – Events Calendar

EventON <= 2.4.1 – Authenticated (Contributor+) Local File Inclusion

The EventON plugin for WordPress is vulnerable to Local File Inclusion via the evo_block_render_callback() function in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute…

Versions affectées

*-2.4.1

Correctif

2.4.2

Publication

07/05/2025

CVE-2024-6180 Élevée · 7,2
EventON – Events Calendar

EventON <= 2.2.15 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.2.15

Correctif

2.2.16

Publication

08/07/2024

CVE-2024-0237 Moyenne · 5,3
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin <= 4.5.8 (Pro) & <= 2.2.7 (Free) – Missing Authorization via eventon_save_virtual_event_settings

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on several function in various versions. This makes it possible for unauthenticated attackers to save virtual event settings.

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

10/01/2024

CVE-2023-6005 Moyenne · 4,4
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Authenticated (Admin+) Stored Cross-Site Scripting

The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

10/01/2024

CVE-2024-0233 Moyenne · 6,1
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Reflected Cross-Site Scripting

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

10/01/2024

CVE-2024-0235 Moyenne · 5,3
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Missing Authorization via get_virtual_users

The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_virtual_users() function in all versions up, and including to 4.5.4 (premium) & 2.2.7 (free). This makes it possible…

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

10/01/2024

CVE-2024-0236 Moyenne · 5,3
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Missing Authorization via config_virtual_event

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the config_virtual_event() function in various versions. This makes it possible for unauthenticated attackers to retrieve the settings of…

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

10/01/2024

CVE-2023-6242 Moyenne · 6,5
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 – Cross-Site Request Forgery via evo_eventpost_update_meta

The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect…

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

09/01/2024

CVE-2023-6244 Moyenne · 6,5
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) – Cross-Site Request Forgery via save_virtual_event_settings

The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation…

Versions affectées

*-2.2.8

Correctif

2.2.9

Publication

09/01/2024

CVE-2023-6158 Moyenne · 6,5
EventON – Events Calendar

EventON – WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 – Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta

The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and…

Versions affectées

*-2.2.7

Correctif

2.2.8

Publication

09/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités