The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
2024-12-16T06:15:08.100
2025-05-14T20:16:11.810
Analyzed
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | stellarwp | the_events_calendar | < 6.8.2.1 | Yes |