rootpwn

medium · CVSS v3 3.8 · EPSS 0.0018

CVE-2026-84743

The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its R…

Description

The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.

Scores

Severity
medium
CVSS v2
4.7
CVSS v3
3.8
CVSS v4
EPSS
0.0018

← All CVEs