The Events Calendar WordPress plugin 6.8.2.1 contains missing access checks in the REST API, letting unauthenticated users access information about password protected events, exploit requires no authentication.
id: CVE-2024-5333
info:
name: WordPress Events Calendar 6.8.2.1 - Information Disclosure
author
...