5.3
CVE-2024-5333
- EPSS 7.34%
- Veröffentlicht 16.12.2024 06:15:08
- Zuletzt bearbeitet 14.05.2025 20:16:11
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event Disclosure
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Mögliche Gegenmaßnahme
The Events Calendar: Update to version 6.8.2.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
The Events Calendar
Version
*-6.8.2
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stellarwp ≫ The Events Calendar SwPlatformwordpress Version < 6.8.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.34% | 0.915 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|