Impact
The vulnerability exists in the Events Calendar WordPress plugin in releases before 6.17.5.1 where an unauthenticated AJAX action accepts the 'view_data' parameter without validation or sanitisation before merging it into the rendering context. Unchecked input allows a remote user to inject any shortcode that the site has registered, causing that shortcode to be processed and executed on the server. Shortcodes can trigger PHP code or other privileged actions, so this flaw can lead to remote code execution, privilege escalation, or other unwanted changes to the WordPress instance.
Affected Systems
The flaw affects the WordPress plugin "The Events Calendar" from an unknown vendor. Versions from 6.12.0 up through any release before 6.17.5.1 are impacted. The issue was fixed in the 6.17.5.1 release, so any installation running an older version is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, suggesting no publicly reported exploitation attempts are known. The flaw is not listed in the CISA KEV catalog. The likely attack path involves any unauthenticated user sending an AJAX request to the plugin’s handler with a crafted 'view_data' payload containing a malicious shortcode. Because the request does not require authentication and the plugin merges the data into its rendering context, an attacker can trigger execution of arbitrary code or actions on the server.
OpenCVE Enrichment