Impact
The EventON Pro WordPress plugin, versions up to 4.9.6, has a missing capability check that allows any authenticated user with a Subscriber role or higher to inject arbitrary web scripts into pages. These scripts execute whenever an affected page is viewed, potentially giving an attacker the ability to steal session cookies, deface content, or perform further malicious actions within the victim site. The weakness is a classic missing authorization flaw, classified as CWE‑862.
Affected Systems
WordPress sites that have the EventON Pro calendar plugin installed on any version through 4.9.6. The plugin can be downloaded from the CodeCanyon marketplace and is commonly used in public‑facing websites running WordPress.
Risk and Exploitability
With a CVSS score of 6.4, the vulnerability is considered medium severity. The EPSS score is less than 1 %, indicating a low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. However, because the flaw permits stored script injection via a role that is granted to typical site subscribers, an attacker only needs legitimate credentials to exploit it, which may make it attractive in targeted attacks.
OpenCVE Enrichment
EUVD