Extension WordPress
Vulnérabilités EventON (Pro) – WordPress Virtual Event Calendar Plugin
Cette page rassemble les failles publiées pour EventON (Pro) – WordPress Virtual Event Calendar Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de EventON (Pro) – WordPress Virtual Event Calendar Plugin
18 fiches
EventON – WordPress Virtual Event Calendar Plugin <= 5.0.11 – Unauthenticated Blind SQL Injection via Search Parameter
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter…
*-5.0.11
Non indiqué
29/06/2026
EventON <= 4.9.12 – Reflected Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-4.9.12
Non indiqué
02/03/2026
EventON Pro <= 4.9.12 – Authenticated (Contributor+) Stored Cross-Site Scripting
The EventON Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.9.12
Non indiqué
29/10/2025
EventON <= 4.9.9 – Missing Authorization
The EventON (Pro) – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.9. This makes it possible…
*-4.9.9
Non indiqué
03/07/2025
EventON (Pro) <= 4.9.9 – Missing Authorization
The EventON (Pro) – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.9. This makes it possible…
*-4.9.9
Non indiqué
16/05/2025
EventON – WordPress Virtual Event Calendar Plugin <= 4.9.6 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6. This makes it possible for authenticated attackers,…
*-4.9.6
4.9.7
16/05/2025
EventON PRO – WordPress Virtual Event Calendar Plugin <= 4.6.8 – Cross-Site Request Forgery via admin_test_email
The EventON PRO – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email…
*-4.6.8
4.7
18/10/2024
EventON <= 4.4.0 – Reflected Cross-Site Scripting
The EventON Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-4.4.0
4.4.1
31/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.8 (Pro) & <= 2.2.7 (Free) – Missing Authorization via eventon_save_virtual_event_settings
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on several function in various versions. This makes it possible for unauthenticated attackers to save virtual event settings.
*-4.5.8
4.5.9
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Authenticated (Admin+) Stored Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible…
*-4.5.4
4.5.5
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Reflected Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it…
*-4.5.4
4.5.5
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Missing Authorization via get_virtual_users
The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_virtual_users() function in all versions up, and including to 4.5.4 (premium) & 2.2.7 (free). This makes it possible…
*-4.5.4
4.5.5
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) – Missing Authorization via config_virtual_event
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the config_virtual_event() function in various versions. This makes it possible for unauthenticated attackers to retrieve the settings of…
*-4.5.4
4.5.5
10/01/2024
EventON – WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 – Cross-Site Request Forgery via evo_eventpost_update_meta
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect…
*-4.5.4
4.5.5
09/01/2024
EventON – WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) – Cross-Site Request Forgery via save_virtual_event_settings
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation…
*-4.5.4
4.5.5
09/01/2024
EventON – WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 – Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta
The EventON – WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and…
*-4.5.4
4.5.5
09/01/2024
EventON <= 2.1 – Insecure Direct Object Reference to Unauthorized Post Access
The EventON plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks affecting the eventon_ics_download AJAX action. This makes it possible…
[*, 4.4)
4.4
19/06/2023
EventON <= 3.0.5 – Reflected Cross-Site Scripting
The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including 3.0.5. This is due to insufficient escaping and sanitization on the q= parameter. This makes it possible for unauthenticated attackers to…
*-3.0.5
3.0.6
27/11/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.