Логотип exploitDog
bind:CVE-2024-0238
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-0238

Количество 2

Количество 2

nvd логотип

CVE-2024-0238

около 2 лет назад

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jgc8-hcph-rwrm

около 2 лет назад

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-0238

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-jgc8-hcph-rwrm

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVSS3: 6.1
1%
Низкий
около 2 лет назад

Уязвимостей на страницу