The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-16036 | The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 02 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-02T15:09:17.461Z
Reserved: 2024-01-04T14:47:37.931Z
Link: CVE-2024-0238
Updated: 2024-08-01T17:41:16.126Z
Status : Modified
Published: 2024-01-16T16:15:14.467
Modified: 2025-06-02T15:15:26.457
Link: CVE-2024-0238
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD