ZeroHour

CVE-2024-5333

PoC
CVSS 3.1
5.3 medium
EPSS
1%p64
Published
()
Modified
Description

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

Vendors
stellarwp
Products
the events calendar
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.