CVE-2024-1295

June 14, 2024, 6:15 a.m.

Product(s) Impacted

The Events Calendar WordPress plugin

  • before 6.4.0.1

The events-calendar-pro WordPress plugin

  • before 6.4.0.1

Description

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

Weaknesses

Date

Published: June 14, 2024, 6:15 a.m.

Last Modified: June 14, 2024, 6:15 a.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

contact@wpscan.com

References