CVE Vulnerabilities

CVE-2024-1295

Published: Jun 14, 2024 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldnt have access to. (e.g. password-protected events, drafts, etc.)

Affected Software

NameVendorStart VersionEnd Version
The_events_calendarTri*6.4.0.1 (excluding)

References