QID 150766
Date Published: 2023-12-25
QID 150766: WordPress The Events Calendar: Arbitrary Password Protected Post Read (CVE-2023-6203)
The Events Calendar is a WordPress plugin, which helps in easily create and manage an events calendar on your WordPress site.
The Events Calendar WordPress plugin discloses the content of password protected posts to unauthenticated users via a crafted request.
Affected Versions:
WordPress The Events Calendar Plugin before 6.2.8.1
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow an unauthorized attacker to gain sensitive information.
Solution
Customers are advised to upgrade to The Events Calendar 6.2.8.2 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer Advisory.
Vendor References
CVEs related to QID 150766
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| The Events Calendar |
|