CVE-2023-6158

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 10, 2024
Updated: Jan 17, 2024
CWE ID 862

Summary

CVE-2023-6158 is a data integrity and confidentiality vulnerability affecting the EventON - WordPress Virtual Event Calendar Plugin. The issue lies in the absence of capability checks on the 'evo_eventpost_update_meta' function, found in all versions up to 4.5.4 for Pro and 2.2.7 for the free version. This shortcoming enables unauthenticated attackers to manipulate arbitrary post metadata, posing a risk for data loss and injection of malicious content.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share