Broken Access Control in EventON Plugin by ashanjay
CVE-2025-47565

6.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
4 July 2025

What is CVE-2025-47565?

A missing authorization vulnerability exists in the EventON plugin developed by ashanjay, which allows unauthenticated attackers to exploit incorrectly configured access control settings. This security concern affects all versions of EventON up to and including 4.9.9, potentially leading to unauthorized access and data exposure. Users are urged to review their access configurations and apply necessary updates to mitigate this risk.

Affected Version(s)

EventON <= 4.9.9

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anhchangmutrang (Patchstack Alliance)
.
CVE-2025-47565 : Broken Access Control in EventON Plugin by ashanjay