The Events Calendar <= 6.2.8 - Information Disclosure
2023-11-20 00:00
Krzysztof ZającStrategic Overview
StatusPatched in 6.2.8.1
Affected PluginThe Events Calendar
Affected Version
< 6.2.8.1CVSS5.3Medium
CVE
CVE-2023-6203Vulnerability Overview
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.2.8 via the get_data function. This makes it possible for unauthenticated attackers to extract sensitive data including private post content, via the REST API.
Technical Analysis
REMEDIATION: Update to version 6.2.8.1, or a newer patched version --- IDENTIFIER: CWE-202 (Exposure of Sensitive Information Through Data Queries) When trying to keep information confidential, an attacker can often infer some of the information by using statistics.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C