peter bassill · operator
$ cve CVE-2023-3219 JSON

CVE-2023-3219 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 7.5% (pctl 94)

Patch early

A public exploit exists.

Description

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS7.52% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-639
On CISA KEVno
Public exploityes
Published2023-07-10
Last modified2026-06-17

Affected (1)

VendorProduct
myeventoneventon

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD