The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
History

Fri, 22 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Theeventscalendar
Theeventscalendar events Calendar Pro
Theeventscalendar the Events Calendar
CPEs cpe:2.3:a:theeventscalendar:events_calendar_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:theeventscalendar:the_events_calendar:*:*:*:*:*:*:*:*
Vendors & Products Theeventscalendar
Theeventscalendar events Calendar Pro
Theeventscalendar the Events Calendar
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Tri
Tri the Events Calendar
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:tri:the_events_calendar:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:tri:the_events_calendar:*:*:pro:*:*:wordpress:*:*
Vendors & Products Tri
Tri the Events Calendar

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-06-14T06:00:02.149Z

Updated: 2025-08-25T14:34:09.387Z

Reserved: 2024-02-06T21:24:31.763Z

Link: CVE-2024-1295

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.358Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T06:15:10.937

Modified: 2024-11-21T08:50:15.410

Link: CVE-2024-1295

cve-icon Redhat

No data.