CVE-2024-5333
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
Record summary
CVE-2024-5333 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
The Events CalendarDefault status: unaffected | CVE List | Before 6.8.2.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Events Calendar 6.8.2.1 - Information DisclosureCVSS 5.3
The Events Calendar WordPress plugin 6.8.2.1 contains missing access checks in the REST API, letting unauthenticated users access information about password protected events, exploit requires no authentication.
Impact
Unauthenticated users can access sensitive event information, potentially leading to information disclosure.
Remediation
Update to version 6.8.2.1 or later.
Source: ProjectDiscovery