WordPress · The Events Calendar · CVE-2026-84741
**Name of the Vulnerable Software and Affected Versions**
The Events Calendar WordPress plugin versions prior to 6.17.5
**Description**
A broken access control issue exists where the software fails to verify the post status of linked records before including their stored details in a public REST API response. This allows unauthenticated users to access and read the contents of non-public venue and organizer records that have not been published. The issue affects over 600,000 active installations.
**Recommendations**
Update The Events Calendar WordPress plugin to version 6.17.5 or later.