VendorsMyeventoneventonall versions
Vulnerabilities

Myeventon EventON

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2023-6158
EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta
Published 2024-01-10 · Modified
6.5EPSS 0.006
CVE-2023-6242
EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Cross-Site Request Forgery via evo_eventpost_update_meta
Published 2024-01-11 · Modified
6.5EPSS 0.003
CVE-2023-6244
EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings
Published 2024-01-11 · Modified
6.5EPSS 0.003
CVE-2025-3527
EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
Published 2025-05-17 · Analyzed
6.4EPSS 0.002
CVE-2020-29395
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
Published 2020-11-30 · Modified
6.11 PoCEPSS 0.129
CVE-2023-7200
EventON < 4.4.1 - Reflected Cross-Site Scripting
Published 2024-01-29 · Modified
6.1EPSS 0.004
CVE-2024-0238
EventON (Free < 2.2.8, Premium < 4.5.6) - Unauthenticated Arbitrary Post Metadata Update
Published 2024-01-16 · Modified
6.1EPSS 0.004
CVE-2024-0233
EventON (Free < 2.2.8, Premium < 4.5.5) - Reflected XSS
Published 2024-01-16 · Modified
6.1EPSS 0.004
CVE-2024-4752
EventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitle
Published 2024-07-13 · Analyzed
5.9EPSS 0.004
CVE-2023-2796
EventON < 2.1.2 - Unauthenticated Event Access
Published 2023-07-10 · Modified
5.31 PoCEPSS 0.427
CVE-2024-0235
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
Published 2024-01-16 · Modified
5.3EPSS 0.380
CVE-2023-3219
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
Published 2023-07-10 · Modified
5.31 PoCEPSS 0.075
CVE-2024-0236
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Virtual Event Password Disclosure
Published 2024-01-16 · Modified
5.3EPSS 0.005
CVE-2024-0237
EventON (Free < 2.2.9, Premium <= 4.5.8) - Unauthenticated Virtual Event Settings Update
Published 2024-01-16 · Modified
5.3EPSS 0.004
CVE-2023-6046
EventON < 2.2 - Admin+ Stored HTML Injection
Published 2024-01-16 · Modified
4.8EPSS 0.004
CVE-2023-6005
EventON (Free < 2.2.7, Premium < 4.5.5) - Admin+ Stored Cross-Site Scripting
Published 2024-01-16 · Modified
4.8EPSS 0.004
CVE-2023-4388
EventON < 2.2 - Admin+ Stored XSS
Published 2023-10-16 · Modified
4.8EPSS 0.004
CVE-2024-6910
EventON < 2.2.17 - Admin+ Stored XSS
Published 2024-09-09 · Analyzed
4.8EPSS 0.004