cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forevent-post event-post

Direction: descending
Apr 23, 2025

Event post # CVE-2025-46228

CVE, Research URL

CVE-2025-46228

Application

Event post

Date
Apr 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.
Affected versions
Min -, max -.
Status
vulnerable
Mar 26, 2025

Event post # CVE-2025-2167

CVE, Research URL

CVE-2025-2167

Application

Event post

Date
Mar 26, 2025
Research Description
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Mar 19, 2025

Event post # CVE-2025-26923

CVE, Research URL

CVE-2025-26923

Application

Event post

Date
-
Research Description
Event post [event-post] < 5.9.9 CVE-2025-26923
Affected versions
Min -, max -.
Status
vulnerable
Jan 26, 2025

Event post # CVE-2025-24585

CVE, Research URL

CVE-2025-24585

Application

Event post

Date
Jan 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS. This issue affects Event post: from n/a through 5.9.7.
Affected versions
Min -, max -.
Status
vulnerable
Nov 07, 2024

Event post # CVE-2024-10186

CVE, Research URL

CVE-2024-10186

Application

Event post

Date
Nov 06, 2024
Research Description
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 23, 2024

Event post # CVE-2024-38735

CVE, Research URL

CVE-2024-38735

Application

Event post

Date
Jul 12, 2024
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in N.O.U.S. Open Useful and Simple Event post allows PHP Local File Inclusion.This issue affects Event post: from n/a through 5.9.5.
Affected versions
Min -, max -.
Status
vulnerable
Jul 13, 2024

Event post # CVE-2024-1375

CVE, Research URL

CVE-2024-1375

Application

Event post

Date
Jul 12, 2024
Research Description
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all versions up to, and including, 5.9.5. This makes it possible for unauthenticated attackers to update post_meta_data via a forged request, granted they can trick a logged-in user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Event post # CVE-2024-1376

CVE, Research URL

CVE-2024-1376

Application

Event post

Date
May 24, 2024
Research Description
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with subscriber access or higher, to update post_meta_data.
Affected versions
Min -, max -.
Status
vulnerable

Event post # CVE-2023-49179

CVE, Research URL

CVE-2023-49179

Application

Event post

Date
Dec 15, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS.This issue affects Event post: from n/a through 5.8.6.
Affected versions
Min -, max -.
Status
vulnerable