First published: Mon Feb 05 2024(Updated: )
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <=6.2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6557 is considered a medium to high severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2023-6557, update the Events Calendar plugin to version 6.2.9 or later.
CVE-2023-6557 is classified as a Sensitive Information Exposure vulnerability.
CVE-2023-6557 affects all versions of The Events Calendar plugin up to and including 6.2.8.2.
Yes, CVE-2023-6557 can be exploited by unauthenticated attackers remotely.