Impact
The vulnerability arises because one family of REST write routes in the Events Calendar WordPress plugin does not enforce per-object capability checks. A user with a low‑privilege role such as Contributor can therefore modify, unpublish, trash, and take ownership of event, venue, and organizer records belonging to other users, including administrators. This flaw permits integrity corruption and makes the site susceptible to defacement, forgeries, and unauthorized data manipulation, and can be leveraged to gain elevated access on the platform.
Affected Systems
The affected product is The Events Calendar WordPress plugin. Versions 6.15.16.1 through 6.17.4.1 are impacted. Upgrading to version 6.17.5 or later resolves the issue.
Risk and Exploitability
The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1% suggests very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers would need authenticated access from a Contributor role and would exploit the REST API endpoints exposed by the plugin. While the risk surface is limited to users with contributor privileges, the ability to take ownership of records can lead to privilege escalation and broader compromise if the attacker can elevate privileges further.
OpenCVE Enrichment