CVE · Medium

CVE-2023-6557 — The Events Calendar [the-events-calendar] < 6.2.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6557 The Events Calendar [the-events-calendar] < 6.2.9 Missing Authorization Medium 5.3 < 6.2.9 6.2.9 2024-01-12

CVE-2023-6557

The Events Calendar plugin for WordPress through version 6.2.8.2 contains a sensitive information exposure vulnerability in the tribe_dropdown AJAX action that is accessible to unauthenticated users. An attacker without login credentials can exploit this flaw to retrieve confidential data such as titles and post identifiers for unpublished content in pending, private, and draft statuses. The vulnerability was patched in version 6.2.9.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.