Access violation vulnerability in EventON 2.1

The EventON plugin for WordPress is not secure in versions up to and including 7.5.4. This means that unauthenticated attackers are able to access and view posts, such as those which are unpublished or protected, through the ICS export feature. This is because security checks and authorization validations are not properly in place.

Detected in:

EventON fixed vulnerable versions: >= * < 4.4
EventON – Events Calendar fixed vulnerable versions:
EventON Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.