Record summary

CVE-2024-5333 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

The Events Calendar

Default status: unaffected

CVE ListBefore 6.8.2.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Events Calendar 6.8.2.1 - Information DisclosureCVSS 5.3

The Events Calendar WordPress plugin 6.8.2.1 contains missing access checks in the REST API, letting unauthenticated users access information about password protected events, exploit requires no authentication.

Impact

Unauthenticated users can access sensitive event information, potentially leading to information disclosure.

Remediation

Update to version 6.8.2.1 or later.

WeaknessesCWE-639
AuthorsDhiyaneshDk
Template tagscvecve2024wordpresswpwp-pluginthe-events-calendardisclosure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: html:"/wp-content/plugins/the-events-calendar/"

Source: ProjectDiscovery

References

2