The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58786 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Oct 2024 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stellarwp
Stellarwp the Events Calendar |
|
| CPEs | cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Tri
Tri the Events Calendar |
Stellarwp
Stellarwp the Events Calendar |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-02T08:35:14.035Z
Reserved: 2023-12-06T14:41:25.107Z
Link: CVE-2023-6557
Updated: 2024-08-02T08:35:14.035Z
Status : Modified
Published: 2024-02-05T22:15:55.767
Modified: 2024-11-21T08:44:05.653
Link: CVE-2023-6557
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD