Описание
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.0.1 (исключая)
cpe:2.3:a:tri:the_events_calendar:*:*:*:*:*:wordpress:*:*
Конфигурация 2Версия до 6.4.0.1 (исключая)
cpe:2.3:a:tri:the_events_calendar:*:*:pro:*:*:wordpress:*:*
EPSS
Процентиль: 78%
0.01115
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-Other
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
EPSS
Процентиль: 78%
0.01115
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-Other