We are using Event On plugin v4.9.12 and have been notified of the vulnerability:
Per Patchstack: Broken Access Control
A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.
Risks
This vulnerability is moderately dangerous and expected to become exploited.
Please see more info at Patchstack website: https://patchstack.com/database/wordpress/plugin/eventon/vulnerability/wordpress-eventon-plugin-4-9-9-broken-access-control-vulnerability-2?_a_id=473
- Aug 29,2025 AT 12:11PM - 5 months agoHello,
Thank you for your messages, I am going to assign this ticket to Ashan and he will be able to take it from here and find you a solution. Please allow some time for him to get back to you, we greatly appreciate your patience and thank you for being a eventon customer! Also please disable any IP blocking on your site if there are any.
this issue is from 4.9.9 and the latest version is newer than that. We have addressed that issue long time ago. They have not updated their database with the fixed version.
You can ignore this issue and if you have a chance please reach out to them and ask them to update their database. — Which we have also done, with no result.
Hello, I reached out to Patchstack and they replied as follows; “Hello, since no patch has
been submitted for us to validate, we can’t update the information. If the
vendor refuses to provide one, we have nothing to verify.”
They also said in a 2nd email… “I’ve reached out to the
vendor again. If they don’t provide a patch for validation, there’s not much we
can do.”
Thank you, I hope this can be resolved soon.
We appreciate the replies.
Virginia for Quetzal Arellano
Thank you for letting us know! Ashan will check this ASAP.
Thank you for updating us Quetzal, we will follow up from our side.
Hello, following up on EventOn providing a patch to Patchstack for validation #395410, please give us a status.
Sorry we are still in the process of processing the patch for them. Their responses for our requests have been far less professional, considering how their reported were using in many services.