CVE Database
/

CVE-2023-2796

Back to search

CVE-2023-2796

Published: Jul 10, 2023

Modified: Feb 13, 2025

PUBLISHED

Description

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

VendorProductVersions

Unknown

EventON

affected
0 - < 2.1.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now