Input validation vulnerability in EventON 2.2.7

The EventON plugin for WordPress has a security issue where hackers can inject harmful code into the settings section. This can happen in versions up to 4.5.4 for the premium version and 2.2.7 for the free version. This can only be done by someone with high-level permissions and it only affects certain types of WordPress installations.

Detected in:

EventON fixed vulnerable versions: >= * <= 4.5.4
EventON – Events Calendar fixed vulnerable versions:
EventON Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.