First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in Themewinter Eventin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through 3.3.52.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eventin | <=3.3.52 | |
WordPress Eventin | <=3.3.52 |
No patched version is available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-49756 is considered high due to the potential for unauthorized access and data exposure.
To fix CVE-2023-49756, update the Themewinter Eventin plugin to version 3.3.52 or later to ensure proper access controls are enforced.
CVE-2023-49756 is caused by missing authorization checks in the Eventin plugin, leading to incorrectly configured access control security levels.
CVE-2023-49756 affects all versions of Themewinter Eventin up to and including version 3.3.52.
Yes, CVE-2023-49756 is also relevant for WordPress users utilizing the Eventin plugin up to version 3.3.52.