5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Affected (1)
Products: Stellarwp: The Events Calendar
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.8.2.1 |
References (1)
Source: contact@wpscan.com
ExploitThird Party Advisory
Timeline
No history available yet.