cleantalk
Vulnerabilities and Security Researches

The Events Calendar, CVE-2026-84741

CVE, Research URL

CVE-2026-84741

Application

The Events Calendar

Published on
Sep 23, 2026
Research Description
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
Affected versions
Min 4.5, max 6.17.5.
Status
vulnerable