Access violation vulnerability in EventON – Events Calendar 2.4.6

The EventON Lite plugin for WordPress has a security issue in versions 2.4.6 and below. This can allow hackers to view information from posts that are password protected, private, or still in draft form. This could be done through the add_single_eventon and add_eventon shortcodes, which do not have enough restrictions on what posts can be accessed. This could potentially give unauthorized users access to sensitive data.

Detected in:

EventON – Events Calendar fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.