Loading HuntDB...

GHSA-j9j6-ccc3-92c8

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers to update plugin settings, including adding stored cross-site scripting to settings options displayed on event calendar pages.

Related CVEs

Key Information

GHSA ID
GHSA-j9j6-ccc3-92c8
Published
July 9, 2024 9:30 AM
Last Modified
July 9, 2024 9:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 23, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.