The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
History

Wed, 14 May 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Stellarwp
Stellarwp the Events Calendar
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:*
Vendors & Products Stellarwp
Stellarwp the Events Calendar

Mon, 16 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Dec 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Title The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-12-16T06:00:05.897Z

Updated: 2024-12-16T16:47:55.953Z

Reserved: 2024-05-24T18:27:38.074Z

Link: CVE-2024-5333

cve-icon Vulnrichment

Updated: 2024-12-16T16:47:45.598Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-16T06:15:08.100

Modified: 2025-05-14T20:16:11.810

Link: CVE-2024-5333

cve-icon Redhat

No data.