CVE-2024-1295
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
- Affected products
- The Events Calendar
- Tri The Events Calendar
- < 6.4.0.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (39th percentile)
- NVD status
- Modified
- Published
- 2024-06-14
CVE-2024-1295 at NVD
1 known exploit for CVE-2024-1295
Proof-of-concept code and exploit modules indexed by Sploitus