CVE-2024-5333
MEDIUMDescription
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Is your site exposed to CVE-2024-5333?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| stellarwp | the_events_calendar |
References
Frequently Asked Questions
What is CVE-2024-5333? +
How severe is CVE-2024-5333? +
What products are affected by CVE-2024-5333? +
How do I check if I'm vulnerable to CVE-2024-5333? +
Related Vulnerabilities
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function …
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions …
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions …
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high …