CVE-2024-5333

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:*

History

14 May 2025, 20:16

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://wpscan.com/vulnerability/764b5a23-8b51-4882-b899-beb54f684984/ - () https://wpscan.com/vulnerability/764b5a23-8b51-4882-b899-beb54f684984/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:*
First Time Stellarwp
Stellarwp the Events Calendar

16 Dec 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-16 06:15

Updated : 2025-05-14 20:16


NVD link : CVE-2024-5333

Mitre link : CVE-2024-5333


JSON object : View

Products Affected

stellarwp

  • the_events_calendar