MEDIUM
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
Published Feb 5, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.56%
Description
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.
Affected products
-
Affected
- ≥ 0, ≤ 6.2.8.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Stellarwp | The Events Calendar | unaffected | Affected
|
- ≤ 6.2.8.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58786 Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3010104%40the-events-calendar%2Ftags%2F6.2.9&old=3010096%40the-events-calendar%2Ftags%2F6.2.9 Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fc40196e-c0f3-4bc6-ac4b-b866902def61?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Feb 5, 2024
Updated Apr 8, 2026
Reserved Dec 6, 2023
Link CVE-2023-6557
CISA Vulnrichment
Updated Feb 7, 2024
Red Hat
No data
GitHub
No data