CVE-2023-6203

Severity
7.5HIGH
EPSS
0.6%
top 31.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18

Description

The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-2q88-68x3-v4pp: The Events Calendar WordPress plugin before 62023-12-18
CVEList
The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read2023-12-18
CVE-2023-6203 (HIGH CVSS 7.5) | The Events Calendar WordPress plugi | cvebase.io