CVE-2023-35777: WordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.1.2.2.
Affected Software
1 affected component
Stellarwp The Events Calendar<=6.1.2.2
Remediation
Information
Update the WordPress The Events Calendar plugin to the latest available version (at least 6.1.3).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-35777?
CVE-2023-35777 is classified as a missing authorization vulnerability that can affect user access levels.
2
How do I fix CVE-2023-35777?
To fix CVE-2023-35777, update The Events Calendar plugin to the latest version beyond 6.1.2.2.
3
What impact does CVE-2023-35777 have on my website?
CVE-2023-35777 can allow unauthorized users to exploit incorrectly configured security controls within The Events Calendar.
4
Which versions of The Events Calendar are affected by CVE-2023-35777?
CVE-2023-35777 affects The Events Calendar from n/a through version 6.1.2.2.
5
Who is the vendor responsible for CVE-2023-35777?
The vendor responsible for CVE-2023-35777 is The Events Calendar.