High 7.1 Unfixed
2026-03-05≤ 4.9.12
CVE-2026-28037
Minimum safe version
4.9.7
Update to 4.9.7 or later to address 13 fixable vulnerabilities
CVE-2026-28037
CVE-2025-63064
WordPress EventON plugin <= 4.9.9 - Broken Access Control vulnerability
EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
WordPress EventON plugin <= 4.9.8 - Broken Access Control vulnerability
CVE-2023-6243
EventON <= 4.4.0 - Reflected Cross-Site Scripting
CVE-2024-0238
CVE-2024-0237
CVE-2024-0236
CVE-2024-0235
CVE-2024-0233
CVE-2023-6005
CVE-2023-6244
CVE-2023-6158
CVE-2023-6242
WordPress eventON premium plugin <= 3.0.5 - Cross-Site Scripting (XSS) vulnerability