Description
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
Published: 2026-09-23
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises because one family of REST write routes in the Events Calendar WordPress plugin does not enforce per-object capability checks. A user with a low‑privilege role such as Contributor can therefore modify, unpublish, trash, and take ownership of event, venue, and organizer records belonging to other users, including administrators. This flaw permits integrity corruption and makes the site susceptible to defacement, forgeries, and unauthorized data manipulation, and can be leveraged to gain elevated access on the platform.

Affected Systems

The affected product is The Events Calendar WordPress plugin. Versions 6.15.16.1 through 6.17.4.1 are impacted. Upgrading to version 6.17.5 or later resolves the issue.

Risk and Exploitability

The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1% suggests very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers would need authenticated access from a Contributor role and would exploit the REST API endpoints exposed by the plugin. While the risk surface is limited to users with contributor privileges, the ability to take ownership of records can lead to privilege escalation and broader compromise if the attacker can elevate privileges further.

Generated by OpenCVE AI on September 23, 2026 at 14:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Events Calendar plugin to version 6.17.5 or later to fix the missing capability check.
  • If an immediate update is not feasible, restrict or disable the affected REST endpoints for Contributor users by implementing an access control rule or temporarily removing Contributor role capabilities from REST operations.
  • Review custom role assignments and enforce strict permission policies to minimize the use of Contributor roles for sensitive data operations.

Generated by OpenCVE AI on September 23, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
Title The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:56:22.720Z

Reserved: 2026-09-02T08:41:21.163Z

Link: CVE-2026-84743

cve-icon Vulnrichment

Updated: 2026-09-23T10:36:01.141Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:03.603

Modified: 2026-09-23T11:17:13.670

Link: CVE-2026-84743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:30:06Z

Weaknesses