cleantalk
Vulnerabilities and Security Researches

The Events Calendar, CVE-2026-84742

CVE, Research URL

CVE-2026-84742

Application

The Events Calendar

Published on
Sep 23, 2026
Research Description
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
Affected versions
Min 6.15.0, max 6.17.5.
Status
vulnerable