سایبرنامه
medium

CVE-2026-84741

The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.

امتیاز CVSS

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

تحلیلِ بردارِ CVSS

CWE
CWE-200
تاریخ انتشار
۱ مهر ۱۴۰۵

منابع