CVE-2024-8700: Total-Soft Event Calendar
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
Affected products
- Total-Soft Event Calendar: up to and including 1.0.4
Published 2025-05-15. Last modified 2026-06-17.