Cross-Site Request Forgery in EventON WordPress Calendar Plugin
CVE-2023-6242
4.3MEDIUM
What is CVE-2023-6242?
The EventON plugin for WordPress exhibits a vulnerability due to insufficient nonce validation within the evo_eventpost_update_meta function. This security flaw allows unauthenticated attackers to potentially manipulate post metadata if they successfully deceive an administrator into executing a malicious request, such as clicking a crafted link. As a result, maintaining robust security protocols and updating to the latest patched versions is essential for all users of the EventON plugin to mitigate this risk.
Affected Version(s)
EventON * <= 2.2.7
EventON Pro * <= 4.5.4