plugin

Eventon Lite Vulnerabilities

44 known security issues reported for the Eventon Lite WordPress plugin. Most recent disclosed Aug 14, 2025.

1 critical 4 high 15 medium 1 low

Running Eventon Lite on your site? Check whether your installed version is affected.

Scan your site free

EventON Lite <= 2.4.7 - Authenticated (Contributor+) Information Disclosure

medium

The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from passw...

CVSS:
4.3
Affected:
up to 2.4.7
Fixed in:
2.4.8
Disclosed:
Aug 14, 2025

CVE-2025-8091 on NVD →

EventON <= 2.4.4 - Missing Authorization

medium

The EventON – Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
May 16, 2025

CVE-2025-48116 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.4.5

unknown

[en] Missing Authorization vulnerability in Ashan Perera EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 2.4.4.

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
May 16, 2025

CVE-2025-48116 on NVD →

EventON <= 2.4.1 - Authenticated (Contributor+) Local File Inclusion

high

The EventON plugin for WordPress is vulnerable to Local File Inclusion via the evo_block_render_callback() function in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the exe...

CVSS:
8.8
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
May 7, 2025

CVE-2025-47494 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.4.2

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.4.1.

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
May 7, 2025

CVE-2025-47494 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.4.1

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.3.2.

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Apr 11, 2025

CVE-2025-32614 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.4.2

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON. This issue affects EventON: from n/a through 2.3.2.

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Apr 10, 2025

CVE-2025-32160 on NVD →

EventON <= 2.4 - Unauthenticated Local File Inclusion

critical

The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obta...

CVSS:
9.8
Affected:
up to 2.4
Fixed in:
2.4.1
Disclosed:
Apr 9, 2025

CVE-2025-32614 on NVD →

EventON <= 2.4.1 - Authenticated (Contributor+) Local File Inclusion

high

The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This c...

CVSS:
8.8
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Apr 4, 2025

CVE-2025-32160 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.17

unknown

[en] The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

Affected:
up to 2.2.17
Fixed in:
2.2.17
Disclosed:
Sep 9, 2024

CVE-2024-6910 on NVD →

EventON <= 2.2.16 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrar...

CVSS:
4.4
Affected:
up to 2.2.16
Fixed in:
2.2.17
Disclosed:
Aug 19, 2024

CVE-2024-6910 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.15

unknown

[en] The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.2.15
Fixed in:
2.2.15
Disclosed:
Jul 13, 2024

CVE-2024-4752 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.16

unknown

[en] The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers to update plugin settings, including adding stored cr...

Affected:
up to 2.2.16
Fixed in:
2.2.16
Disclosed:
Jul 9, 2024

CVE-2024-6180 on NVD →

EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates

high

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers to update plugin settings, including adding stored cross-s...

CVSS:
7.2
Affected:
up to 2.2.15
Fixed in:
2.2.16
Disclosed:
Jul 8, 2024

CVE-2024-6180 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.15

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashan Jay EventON allows Stored XSS.This issue affects EventON: from n/a through 2.2.14.

Affected:
up to 2.2.15
Fixed in:
2.2.15
Disclosed:
May 3, 2024

CVE-2024-33940 on NVD →

EventON <= 2.2.14 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrar...

CVSS:
4.4
Affected:
up to 2.2.14
Fixed in:
2.2.15
Disclosed:
Apr 30, 2024

CVE-2024-33940 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.8

unknown

[en] The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 16, 2024

CVE-2024-0238 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.9

unknown

[en] The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Jan 16, 2024

CVE-2024-0237 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.8

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 16, 2024

CVE-2024-0236 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.8

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 16, 2024

CVE-2024-0235 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.8

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 16, 2024

CVE-2024-0233 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.7

unknown

[en] The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite se...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Jan 16, 2024

CVE-2023-6005 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2

unknown

[en] The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Jan 16, 2024

CVE-2023-6046 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.9

unknown

[en] The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation on the save_virtual_event_settings function. This makes it possible for unaut...

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Jan 11, 2024

CVE-2023-6244 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.8

unknown

[en] The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect nonce validation on the evo_eventpost_update_meta function. This makes it possible for...

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 11, 2024

CVE-2023-6242 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Reflected Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
6.1
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 10, 2024

CVE-2024-0233 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.8 (Pro) & <= 2.2.7 (Free) - Missing Authorization via eventon_save_virtual_event_settings

medium

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on several function in various versions. This makes it possible for unauthenticated attackers to save virtual event settings.

CVSS:
5.3
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 10, 2024

CVE-2024-0237 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Missing Authorization via get_virtual_users

medium

The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_virtual_users() function in all versions up, and including to 4.5.4 (premium) & 2.2.7 (free). This makes it possible for unauthenticated attackers to retrieve email addresses from the blog.

CVSS:
5.3
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 10, 2024

CVE-2024-0235 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Missing Authorization via config_virtual_event

medium

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the config_virtual_event() function in various versions. This makes it possible for unauthenticated attackers to retrieve the settings of arbitrary virtual events which can contain password da...

CVSS:
5.3
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 10, 2024

CVE-2024-0236 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.7 (Free) - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.5.4 (premium) & 2.2.7 (free) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...

CVSS:
4.4
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 10, 2024

CVE-2023-6005 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.8

unknown

[en] The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possib...

Affected:
up to 2.2.8
Fixed in:
2.2.8
Disclosed:
Jan 10, 2024

CVE-2023-6158 on NVD →

EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta

medium

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including, 4.5.4 (for Pro) and 2.2.7 (for free). This makes it possible fo...

CVSS:
6.5
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 9, 2024

CVE-2023-6158 on NVD →

EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Cross-Site Request Forgery via evo_eventpost_update_meta

medium

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (for Pro) & 2.2.7 (for Free). This is due to missing or incorrect nonce validation on the evo_eventpost_update_meta function. This makes it possible for unau...

CVSS:
6.5
Affected:
up to 2.2.7
Fixed in:
2.2.8
Disclosed:
Jan 9, 2024

CVE-2023-6242 on NVD →

EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings

medium

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 (Pro) & 2.2.8 (Free). This is due to missing or incorrect nonce validation on the save_virtual_event_settings function. This makes it possible for unauthenti...

CVSS:
6.5
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Jan 9, 2024

CVE-2023-6244 on NVD →

EventON <= 2.1.7 - Authenticated (Admin+) HTML Injection

low

The EventON plugin for WordPress is vulnerable to HTML Injection via admin settings in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary HTML in page...

CVSS:
3
Affected:
up to 2.1.7
Fixed in:
2.2
Disclosed:
Nov 9, 2023

CVE-2023-6046 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2.3

unknown

[en] The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Oct 21, 2023

CVE-2023-4635 on NVD →

EventON <= 2.2.2 - Reflected Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Oct 20, 2023

CVE-2023-4635 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.2

unknown

[en] The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Oct 16, 2023

CVE-2023-4388 on NVD →

EventON <= 2.1.7 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

CVSS:
4.4
Affected:
up to 2.1.7
Fixed in:
2.2
Disclosed:
Sep 21, 2023

CVE-2023-4388 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.1.2

unknown

[en] The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of t...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jul 10, 2023

CVE-2023-3219 on NVD →

EventON &#8211; Events Calendar [eventon-lite] < 2.1.2

unknown

[en] The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jul 10, 2023

CVE-2023-2796 on NVD →

EventON <= 2.1 - Insecure Direct Object Reference to Unauthorized Post Access

high

The EventON plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks affecting the eventon_ics_download AJAX action. This makes it possible for unauthenticated attackers to view arbitrary posts (e.g., u...

CVSS:
7.5
Affected:
up to 2.1
Fixed in:
2.1.2
Disclosed:
Jun 19, 2023

CVE-2023-3219 on NVD →

EventON <= 2.1 - Missing Authorization to Event Access

medium

The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the eventon_ics_download function in versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to view private or protected events.

CVSS:
5.3
Affected:
up to 2.1
Fixed in:
2.1.2
Disclosed:
Jun 19, 2023

CVE-2023-2796 on NVD →

EventON &#8211; Events Calendar [eventon-lite] <= 2.4.6 (unfixed)

unknown
Affected:
up to 2.4.6
Fix:
No patched version reported

CVE-2025-8091 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database