The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Stellarwp
Stellarwp the Events Calendar |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Stellarwp
Stellarwp the Events Calendar |
Mon, 16 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 16 Dec 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. | |
Title | The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-12-16T06:00:05.897Z
Updated: 2024-12-16T16:47:55.953Z
Reserved: 2024-05-24T18:27:38.074Z
Link: CVE-2024-5333

Updated: 2024-12-16T16:47:45.598Z

Status : Analyzed
Published: 2024-12-16T06:15:08.100
Modified: 2025-05-14T20:16:11.810
Link: CVE-2024-5333

No data.