CVE · Medium

CVE-2024-5333 — The Events Calendar [the-events-calendar] < 6.8.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5333 The Events Calendar [the-events-calendar] < 6.8.2.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 6.8.2.1 6.8.2.1 2024-11-25

CVE-2024-5333

The Events Calendar plugin contains an information disclosure vulnerability in versions up to 6.8.2 where the /wp-json/tribe/events/v1/events/ REST API endpoint fails to properly validate access restrictions. Unauthenticated users can exploit this flaw to retrieve sensitive data from password-protected events that should remain inaccessible to them. The vulnerability affects all versions prior to 6.8.2.1 and requires no authentication to exploit.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.