CVE-2024-37518: WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.5.1.4.
Affected Software
1 affected component
Stellarwp The Events Calendar<=6.5.1.4
Remediation
Information
Update the WordPress The Events Calendar plugin to the latest available version (at least 6.5.1.5).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37518?
CVE-2024-37518 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions on behalf of the user.
2
How do I fix CVE-2024-37518?
To fix CVE-2024-37518, update The Events Calendar plugin to version 6.5.1.5 or later.
3
Which versions of The Events Calendar are affected by CVE-2024-37518?
CVE-2024-37518 affects The Events Calendar versions from n/a through 6.5.1.4.
4
What type of vulnerability is CVE-2024-37518?
CVE-2024-37518 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Are there any known exploits for CVE-2024-37518?
As of now, there are no public exploits reported for CVE-2024-37518.