Cross-Site Request Forgery Vulnerability in The Events Calendar by Modern Tribe
CVE-2025-24537
5.4MEDIUM
What is CVE-2025-24537?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in The Events Calendar, a popular event management plugin developed by Modern Tribe. This vulnerability allows an attacker to perform unauthorized actions on behalf of an authenticated user without their consent. It affects all versions of The Events Calendar up to and including version 6.7.0, posing a risk for users who have not updated to the latest version. Mitigating this vulnerability is crucial to safeguarding user accounts and maintaining the integrity of event management functionalities.
Affected Version(s)
The Events Calendar <= 6.7.0