Impact
The vulnerability resides in the Events Calendar WordPress plugin prior to version 6.17.3.1. The plugin’s public REST API does not enforce permission checks on non‑public events, venues, or organizers, allowing any user authenticated with a low‑privilege role such as contributor to retrieve the full content of every unpublished record. This leads to accidental exposure of sensitive information belonging to other users, compromising confidentiality and potentially revealing private event details.
Affected Systems
All WordPress sites that install The Events Calendar plugin version 6.17.3.0 or earlier are affected. The issue applies to the plugin’s REST endpoints that serve event, venue, and organizer data. Users logged in as contributors, authors, or other roles lacking full read permissions can trigger the disclosure.
Risk and Exploitability
The vulnerability is exploitable via an authenticated REST request that any logged‑in user can send, so attackers need only an account with contributor privileges. While the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, the absence of authorization checks constitutes a clear information‑exposure risk. A CVSS score is not supplied, but the impact on confidentiality ranks high, and the attack is straightforward once a user has access to the WordPress REST API.
OpenCVE Enrichment