Impact
The Events Calendar plugin for WordPress is vulnerable to information exposure in versions up to and including 6.15.2 due to a flaw in the REST endpoint. The weakness, identified as CWE‑200, allows attackers to read data that should be protected by password protection on vendors or venues. The exposure can reveal sensitive data such as vendor identities, venue details, or other private attributes, potentially compromising confidentiality of site content.
Affected Systems
StellarWP’s The Events Calendar plugin, versions 6.15.2 and earlier, running on WordPress sites are affected. The vulnerability is tied to the plugin’s REST API component and is present in all releases up to the specified version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of 1% suggests a relatively low probability of exploitation but it is not zero. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Attackers can reach the flaw by sending unauthenticated requests to the plugin’s REST endpoint, as the authentication check is missing in the endpoint logic. If successful, attackers could retrieve protected information without any privilege.
OpenCVE Enrichment
EUVD