Cross-Site Request Forgery Vulnerability in The Events Calendar by Modern Tribe
CVE-2025-24537
What is CVE-2025-24537?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in The Events Calendar, a popular event management plugin developed by Modern Tribe. This vulnerability allows an attacker to perform unauthorized actions on behalf of an authenticated user without their consent. It affects all versions of The Events Calendar up to and including version 6.7.0, posing a risk for users who have not updated to the latest version. Mitigating this vulnerability is crucial to safeguarding user accounts and maintaining the integrity of event management functionalities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
The Events Calendar <= 6.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved