Jetpack has been flagging Eventon for a few version at this point.
What did Jetpack find?
The plugin eventON (version 5.0.10) has a known vulnerability. EventON Pro <= 4.9.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
Linking to this older report https://wpscan.com/vulnerability/7004070f-7de8-4759-8e65-c77318220754/
EventON Pro <= 4.9.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
Reading through patches I had assumed this has been fixed, has their scan index updated or is this a newer discovery?
Hello,
Thank you for your messages!
I am going to escalate this ticket to development to help in here. Please allow us some time to address this, and we truly appreciate your patience. Thank you for being a valued EventON customer!