CVE-2023-49756: WordPress Eventin plugin <= 3.3.52 - Authenticated Notice Dismissal Vulnerability
Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through <= 3.3.52.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49756?
The severity of CVE-2023-49756 is considered high due to the potential for unauthorized access and data exposure.
How do I fix CVE-2023-49756?
To fix CVE-2023-49756, update the Themewinter Eventin plugin to version 3.3.52 or later to ensure proper access controls are enforced.
What causes CVE-2023-49756?
CVE-2023-49756 is caused by missing authorization checks in the Eventin plugin, leading to incorrectly configured access control security levels.
Which versions of Themewinter Eventin are affected by CVE-2023-49756?
CVE-2023-49756 affects all versions of Themewinter Eventin up to and including version 3.3.52.
Is CVE-2023-49756 relevant for WordPress users?
Yes, CVE-2023-49756 is also relevant for WordPress users utilizing the Eventin plugin up to version 3.3.52.