CVE-2024-5333: Stellarwp The Events Calendar

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

Affected products

  • Stellarwp The Events Calendar: before 6.8.2.1 (fixed in 6.8.2.1)

Published 2024-12-16. Last modified 2026-06-17.