CVE-2023-6203: The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read
Published Dec 18, 2023
·Updated
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request
Affected Software
1 affected component
Stellarwp The Events Calendar Wordpress<6.2.8.1
Event History
Dec 18, 2023
CVE Published
08:07 PM
Data Sourced
08:07 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6203?
CVE-2023-6203 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-6203?
To fix CVE-2023-6203, update the Events Calendar plugin to version 6.2.8.1 or later.
3
Who is affected by CVE-2023-6203?
Users of the Events Calendar WordPress plugin before version 6.2.8.1 are affected by CVE-2023-6203.
4
What types of data are compromised in CVE-2023-6203?
CVE-2023-6203 allows the disclosure of the content of password protected posts to unauthenticated users.
5
What causes CVE-2023-6203?
CVE-2023-6203 is caused by a vulnerability in the Events Calendar WordPress plugin that improperly handles requests for protected content.