CVE-2026-84742
Received Received - Intake

Unauthenticated Content Publishing in The Events Calendar WordPress Plugin

Vulnerability report for CVE-2026-84742, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moderntribe the_events_calendar From 6.15.0 (inc) to 6.17.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a broken access control issue in The Events Calendar WordPress plugin versions 6.15.0 to 6.17.4.1. It allows users with roles like Contributor, who normally cannot publish content, to bypass editorial review and publish content directly through the plugin's REST API due to a failure to verify required capabilities before creating or updating content.

Detection Guidance

Check the installed version of The Events Calendar plugin. If it is between 6.15.0 and 6.17.4.1, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

If you use The Events Calendar plugin versions 6.15.0 to 6.17.4.1, an attacker with a Contributor role or similar could publish unauthorized content without going through the normal editorial review process. This could lead to the spread of misinformation, inappropriate content, or other disruptions on your WordPress site.

Compliance Impact

This vulnerability allows unauthorized users to publish content directly, bypassing editorial review. This could lead to non-compliance with data protection regulations like GDPR or HIPAA if sensitive or regulated content is published without proper oversight or approval.

Mitigation Strategies

Update The Events Calendar plugin to version 6.17.5 or later immediately. Disable the plugin temporarily if an update is not immediately available, or restrict user roles to prevent unauthorized publishing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84742. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart