Cross-Site Request Forgery Vulnerability in The Events Calendar by Modern Tribe
CVE-2025-24537

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
27 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in The Events Calendar, a popular event management plugin developed by Modern Tribe. This vulnerability allows an attacker to perform unauthorized actions on behalf of an authenticated user without their consent. It affects all versions of The Events Calendar up to and including version 6.7.0, posing a risk for users who have not updated to the latest version. Mitigating this vulnerability is crucial to safeguarding user accounts and maintaining the integrity of event management functionalities.

Affected Version(s)

The Events Calendar <= 6.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.