CVE-2024-1295: The Events Calendar (Free < 6.4.0.1, Pro < 6.4.0.1) - Contributor+ Arbitrary Events Access
Published Jun 14, 2024
·Updated
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
Affected Software
2 affected components
Tri The Events Calendar WordPress<6.4.0.1
Tri The Events Calendar WordPress<6.4.0.1
Event History
Jun 14, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-1295?
CVE-2024-1295 has a high severity due to unauthorized access to sensitive event details.
2
How do I fix CVE-2024-1295?
To fix CVE-2024-1295, update The Events Calendar and Events Calendar Pro plugins to version 6.4.0.1 or later.
3
What kind of user roles are affected by CVE-2024-1295?
CVE-2024-1295 affects users with at least the contributor role.
4
What data is exposed by CVE-2024-1295?
CVE-2024-1295 allows leakage of details about password-protected events and drafts.
5
Which versions of The Events Calendar are vulnerable to CVE-2024-1295?
The vulnerable versions of The Events Calendar and Events Calendar Pro are those before 6.4.0.1.