CVE-2024-5333: The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure

Description

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

Classification

CVE ID: CVE-2024-5333

Affected Products

Vendor: Unknown

Product: The Events Calendar

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://wpscan.com/vulnerability/764b5a23-8b51-4882-b899-beb54f684984/

Timeline