medium · CVSS v3 5.3 · EPSS 0.00199
CVE-2026-84741
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding the…
Description
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00199