The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
History

Wed, 04 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Total-soft
Total-soft event Calendar
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:total-soft:event_calendar:*:*:*:*:*:wordpress:*:*
Vendors & Products Total-soft
Total-soft event Calendar

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
Title Event Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletion
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:17.831Z

Updated: 2025-05-20T19:12:51.900Z

Reserved: 2024-09-11T13:54:25.239Z

Link: CVE-2024-8700

cve-icon Vulnrichment

Updated: 2025-05-19T20:23:57.221Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:59.547

Modified: 2025-06-04T20:07:46.120

Link: CVE-2024-8700

cve-icon Redhat

No data.