EventON <= 2.1 - Insecure Direct Object Reference to Unauthorized Post Access

2023-06-19 00:00
Miguel Santareno

Strategic Overview

Status
Patched in 2.1.2
Affected Version<= 2.1
CVSS7.5High
CVECVE-2023-3219
View all EventON – Events Calendar vulnerabilities

Vulnerability Overview

The EventON plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks affecting the eventon_ics_download AJAX action. This makes it possible for unauthenticated attackers to view arbitrary posts (e.g., unpublished or protected) via the ICS export feature.

Technical Analysis

REMEDIATION: Update to version 2.1.2, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C