CVE Vulnerabilities

CVE-2024-1295

Published: Jun 14, 2024 | Modified: Aug 07, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldnt have access to. (e.g. password-protected events, drafts, etc.)

Affected Software

Name Vendor Start Version End Version
The_events_calendar Tri * 6.4.0.1 (excluding)

References