plugin

Eventon Vulnerabilities

33 known security issues reported for the Eventon WordPress plugin. Most recent disclosed Jun 29, 2026.

1 critical 1 high 16 medium

Running Eventon on your site? Check whether your installed version is affected.

Scan your site free

EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter

critical

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it poss...

CVSS:
9.8
Affected:
up to 5.0.11
Fix:
No patched version reported
Disclosed:
Jun 29, 2026

CVE-2026-9711 on NVD →

EventON <= 4.9.12 - Reflected Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 4.9.12
Fix:
No patched version reported
Disclosed:
Mar 2, 2026

CVE-2026-28037 on NVD →

EventON Pro <= 4.9.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The EventON Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 4.9.12
Fix:
No patched version reported
Disclosed:
Oct 29, 2025

CVE-2025-63064 on NVD →

EventON [eventON] <= 4.9.9 (unfixed)

unknown

[en] Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9.

Affected:
up to 4.9.9
Fix:
No patched version reported
Disclosed:
Jul 4, 2025

CVE-2025-47565 on NVD →

EventON <= 4.9.9 - Missing Authorization

medium

The EventON (Pro) - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an una...

CVSS:
4.3
Affected:
up to 4.9.9
Fix:
No patched version reported
Disclosed:
Jul 3, 2025

CVE-2025-47565 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbit...

CVSS:
6.4
Affected:
up to 4.9.6
Fixed in:
4.9.7
Disclosed:
May 16, 2025

CVE-2025-3527 on NVD →

EventON (Pro) <= 4.9.9 - Missing Authorization

medium

The EventON (Pro) - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.9.9
Fix:
No patched version reported
Disclosed:
May 16, 2025

CVE-2025-47564 on NVD →

EventON [eventON] <= 4.9.9 (unfixed)

unknown

[en] Missing Authorization vulnerability in ashanjay EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 4.9.9.

Affected:
up to 4.9.9
Fix:
No patched version reported
Disclosed:
May 16, 2025

CVE-2025-47564 on NVD →

EventON [eventON] < 4.7

unknown

[en] The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email function. This makes it possible for unauthenticated attackers to send...

Affected:
up to 4.7
Fixed in:
4.7
Disclosed:
Oct 19, 2024

CVE-2023-6243 on NVD →

EventON PRO - WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email

medium

The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email function. This makes it possible for unauthenticated attackers to send test...

CVSS:
4.3
Affected:
up to 4.6.8
Fixed in:
4.7
Disclosed:
Oct 18, 2024

CVE-2023-6243 on NVD →

EventON <= 4.4.0 - Reflected Cross-Site Scripting

medium

The EventON Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.4.0
Fixed in:
4.4.1
Disclosed:
Jan 31, 2024

CVE-2023-7200 on NVD →

EventON [eventON] < 4.4.1

unknown

[en] The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 4.4.1
Fixed in:
4.4.1
Disclosed:
Jan 29, 2024

CVE-2023-7200 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite se...

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 16, 2024

CVE-2023-6005 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 16, 2024

CVE-2024-0233 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 16, 2024

CVE-2024-0235 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 16, 2024

CVE-2024-0236 on NVD →

EventON [eventON] < 4.5.9

unknown

[en] The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

Affected:
up to 4.5.9
Fixed in:
4.5.9
Disclosed:
Jan 16, 2024

CVE-2024-0237 on NVD →

EventON [eventON] < 4.5.6

unknown

[en] The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

Affected:
up to 4.5.6
Fixed in:
4.5.6
Disclosed:
Jan 16, 2024

CVE-2024-0238 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect nonce validation on the evo_eventpost_update_meta function. This makes it possible for...

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 11, 2024

CVE-2023-6242 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation on the save_virtual_event_settings function. This makes it possible for unaut...

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 11, 2024

CVE-2023-6244 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Reflected Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
6.1
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 10, 2024

CVE-2024-0233 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Missing Authorization via config_virtual_event

medium

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the config_virtual_event() function in various versions. This makes it possible for unauthenticated attackers to retrieve the settings of arbitrary virtual events which can contain password da...

CVSS:
5.3
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 10, 2024

CVE-2024-0236 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Missing Authorization via get_virtual_users

medium

The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_virtual_users() function in all versions up, and including to 4.5.4 (premium) & 2.2.7 (free). This makes it possible for unauthenticated attackers to retrieve email addresses from the blog.

CVSS:
5.3
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 10, 2024

CVE-2024-0235 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.8 (Pro) & <= 2.2.7 (Free) - Missing Authorization via eventon_save_virtual_event_settings

medium

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on several function in various versions. This makes it possible for unauthenticated attackers to save virtual event settings.

CVSS:
5.3
Affected:
up to 4.5.8
Fixed in:
4.5.9
Disclosed:
Jan 10, 2024

CVE-2024-0237 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...

CVSS:
4.4
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 10, 2024

CVE-2023-6005 on NVD →

EventON [eventON] < 4.5.5

unknown

[en] The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possib...

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Jan 10, 2024

CVE-2023-6158 on NVD →

EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta

medium

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possible fo...

CVSS:
6.5
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 9, 2024

CVE-2023-6158 on NVD →

EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Cross-Site Request Forgery via evo_eventpost_update_meta

medium

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect nonce validation on the evo_eventpost_update_meta function. This makes it possible for unau...

CVSS:
6.5
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 9, 2024

CVE-2023-6242 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings

medium

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation on the save_virtual_event_settings function. This makes it possible for unauthenti...

CVSS:
6.5
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jan 9, 2024

CVE-2023-6244 on NVD →

EventON <= 2.1 - Insecure Direct Object Reference to Unauthorized Post Access

high

The EventON plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks affecting the eventon_ics_download AJAX action. This makes it possible for unauthenticated attackers to view arbitrary posts (e.g., u...

CVSS:
7.5
Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Jun 19, 2023

CVE-2023-3219 on NVD →

EventON [eventON] < 3.0.6

unknown

[en] The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Nov 30, 2020

CVE-2020-29395 on NVD →

EventON <= 3.0.5 - Reflected Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including 3.0.5. This is due to insufficient escaping and sanitization on the q= parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 3.0.5
Fixed in:
3.0.6
Disclosed:
Nov 27, 2020

CVE-2020-29395 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database