CVE-2025-24537Cross-Site Request Forgery in THE Events Calendar

Severity
7.5HIGH
No vector
EPSS
0.1%
top 77.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27

Description

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.7.0.

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-q427-677q-cw5w: Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery2025-01-27
CVEList
WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability2025-01-27

📋Vendor Advisories

1
Microsoft
Infinite loop in parsing in go/scanner2023-04-11
CVE-2025-24537 — Cross-Site Request Forgery | cvebase