CVE-2024-5333
PoC —CVSS 3.1
5.3 medium
EPSS
1%p64
Published
()
Modified
Description
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
- Vendors
- stellarwp
- Products
- the events calendar
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.