CVE Vulnerabilities

CVE-2024-5333

Published: Dec 16, 2024 | Modified: May 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

Affected Software

Name Vendor Start Version End Version
The_events_calendar Stellarwp * 6.8.2.1 (excluding)

References