The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58303 | The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 13 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-13T19:10:24.185Z
Reserved: 2023-11-09T03:06:30.565Z
Link: CVE-2023-6046
Updated: 2024-08-02T08:21:17.064Z
Status : Modified
Published: 2024-01-16T16:15:13.580
Modified: 2025-06-13T20:15:22.677
Link: CVE-2023-6046
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD