
🚨 CVE-2024-8016: The Events Calendar Pro <= 7.0.2 ... Admin-level PHP object injection drops to contributor access when paired with Elementor - 9.1 CVSS with POP chains means... https://zerodaysignal.com/vulnerability/CVE-2024-8016 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces CVE-2024‑8016 for The Events Calendar Pro, noting an admin‑level PHP object injection that drops to contributor access with Elementor, a CVSS score of 9.1, and provides a link to a vulnerability page.
