PT-2026-97175 · WordPress · The Events Calendar
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Events Calendar WordPress plugin versions prior to 6.17.5
Description
The plugin fails to verify the necessary permissions required to publish content when creating or updating entries via its REST API. This allows users with restricted roles, such as contributors, to publish content directly, effectively bypassing the standard editorial review process.
Recommendations
Update The Events Calendar WordPress plugin to version 6.17.5 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Events Calendar