CVE Database /
CVE-2023-6557
CVE · Medium
CVE-2023-6557 — The Events Calendar [the-events-calendar] < 6.2.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6557
|
The Events Calendar [the-events-calendar] < 6.2.9 |
Missing Authorization |
Medium
5.3
|
< 6.2.9
|
6.2.9 |
2024-01-12 |
—
|
CVE-2023-6557
The Events Calendar plugin for WordPress through version 6.2.8.2 contains a sensitive information exposure vulnerability in the tribe_dropdown AJAX action that is accessible to unauthenticated users. An attacker without login credentials can exploit this flaw to retrieve confidential data such as titles and post identifiers for unpublished content in pending, private, and draft statuses. The vulnerability was patched in version 6.2.9.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings