Cross-Site Request Forgery in EventON WordPress Calendar Plugin
CVE-2023-6242
What is CVE-2023-6242?
The EventON plugin for WordPress exhibits a vulnerability due to insufficient nonce validation within the evo_eventpost_update_meta function. This security flaw allows unauthenticated attackers to potentially manipulate post metadata if they successfully deceive an administrator into executing a malicious request, such as clicking a crafted link. As a result, maintaining robust security protocols and updating to the latest patched versions is essential for all users of the EventON plugin to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EventON * <= 2.2.7
EventON Pro * <= 4.5.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved