medium · CVSS v3 3.8 · EPSS 0.0018
CVE-2026-84743
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its R…
Description
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
Scores
- Severity
- medium
- CVSS v2
- 4.7
- CVSS v3
- 3.8
- CVSS v4
- —
- EPSS
- 0.0018