Description
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15222 | The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars. |
References
History
Wed, 04 Jun 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Total-soft
Total-soft event Calendar |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:total-soft:event_calendar:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Total-soft
Total-soft event Calendar |
Tue, 20 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars. | |
| Title | Event Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletion | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-08-27T12:00:57.959Z
Reserved: 2024-09-11T13:54:25.239Z
Link: CVE-2024-8700
Updated: 2025-05-19T20:23:57.221Z
Status : Analyzed
Published: 2025-05-15T20:15:59.547
Modified: 2025-06-04T20:07:46.120
Link: CVE-2024-8700
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD