Page 2 of 6 results (0.005 seconds)

CVSS: 4.3EPSS: %CPEs: 1EXPL: 0

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_ical_output_for_an_event() function in versions up to, and including, 6.1.2.2. This makes it possible for unauthenticated attackers to view arbitrary/private event content. • CWE-862: Missing Authorization •