cleantalk
Vulnerabilities and Security Researches

The Events Calendar, CVE-2024-1295

CVE, Research URL

CVE-2024-1295

Application

The Events Calendar

Published on
Jun 14, 2024
Research Description
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
Affected versions
max 6.4.0.1.
Status
vulnerable