← WordPress Vulnerabilities
WordPress security by component

EventON

EventON is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Mar 05, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: eventon

CVE-2026-28037: EventON: Cross-site scripting

EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 05, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 05, 2026 CVE-2026-28037
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Dec 09, 2025 CVE-2025-63064
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jul 04, 2025 CVE-2025-47565
EventON: A security weakness
EventON is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
May 17, 2025 CVE-2025-3527
EventON Pro: A security weakness
EventON Pro is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.4
NVD5.4
May 16, 2025 CVE-2025-47564
EventON: A security weakness
EventON is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 09, 2024 CVE-2024-6910
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 13, 2024 CVE-2024-4752
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Jan 29, 2024 CVE-2023-7200
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 16, 2024 CVE-2024-0238
EventON Premium: A security weakness
EventON Premium is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.1
NVD6.1
Jan 16, 2024 CVE-2024-0237
EventON: A security weakness
EventON is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jan 16, 2024 CVE-2024-0236
EventON: A security weakness
EventON is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jan 16, 2024 CVE-2024-0235
EventON: A security weakness
EventON is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jan 16, 2024 CVE-2024-0233
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 16, 2024 CVE-2023-6046
EventON: A security weakness
EventON is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.8
NVD4.8
Jan 16, 2024 CVE-2023-6005
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jan 11, 2024 CVE-2023-6244
EventON - WordPress Virtual Event Calendar Plugin: Cross-site request forgery
EventON - WordPress Virtual Event Calendar Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD4.3
Jan 11, 2024 CVE-2023-6242
EventON - WordPress Virtual Event Calendar Plugin: Cross-site request forgery
EventON - WordPress Virtual Event Calendar Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD4.3
Jan 10, 2024 CVE-2023-6158
EventON - WordPress Virtual Event Calendar Plugin: A security weakness
EventON - WordPress Virtual Event Calendar Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Oct 16, 2023 CVE-2023-4388
EventON: Cross-site scripting
EventON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 10, 2023 CVE-2023-3219
EventON: A security weakness
EventON is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jul 10, 2023 CVE-2023-2796
EventON: A security weakness
EventON is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 30, 2020 CVE-2020-29395
Eventon: Cross-site scripting
Eventon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1