CVE-2026-84743
Received Received - Intake

Unauthorized Record Modification in The Events Calendar WordPress Plugin

Vulnerability report for CVE-2026-84743, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
the_events_calendar the_events_calendar to 6.17.5 (exc)
moderntribe the_events_calendar to 6.17.5 (exc)
moderntribe the_events_calendar From 6.15.16.1 (inc) to 6.17.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect authorization issue in The Events Calendar WordPress plugin. It allows users with low-privilege roles, such as contributors, to modify, unpublish, trash, or take ownership of events, venues, or organizers created by other users, including administrators. The flaw exists because certain REST write routes do not perform proper per-object capability checks.

Detection Guidance

Check the installed version of The Events Calendar plugin using WordPress admin panel or run the command: wp plugin list --name=the-events-calendar. If the version is between 6.15.16.1 and 6.17.4.1, the system is vulnerable.

Impact Analysis

If you are a WordPress site administrator, an attacker with a low-privilege role could modify or delete your events, venues, or organizers. This could disrupt your website's functionality, alter content without permission, or take control of your site's data.

Compliance Impact

This vulnerability could lead to unauthorized modifications or deletions of sensitive data, potentially violating compliance requirements for GDPR or HIPAA. Unauthorized changes to user data or records may result in data integrity issues and legal penalties.

Mitigation Strategies

Update The Events Calendar plugin to version 6.17.5 or later immediately. Disable write access for low-privilege roles like contributors until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84743. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart