CVE-2023-6557: The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wpajaxnoprivtribedropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6557?
CVE-2023-6557 is considered a medium to high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2023-6557?
To fix CVE-2023-6557, update the Events Calendar plugin to version 6.2.9 or later.
What type of vulnerability is CVE-2023-6557?
CVE-2023-6557 is classified as a Sensitive Information Exposure vulnerability.
Who is affected by CVE-2023-6557?
CVE-2023-6557 affects all versions of The Events Calendar plugin up to and including 6.2.8.2.
Can CVE-2023-6557 be exploited remotely?
Yes, CVE-2023-6557 can be exploited by unauthenticated attackers remotely.