The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · The Events Calendarpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/c7d3b1c5-3b3a-4359-aa41-0dfccb091fa4/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.