All vulnerabilities
CVE-2026-84743
Low
CVSS 3.8
The Events Calendar 6.15.16.1 – 6.17.4.1 – Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes
| Vendor | The Events Calendar / StellarWP |
|---|---|
| Product | The Events Calendar |
| Affected versions | 6.15.16.1 – 6.17.4.1 |
| Weakness | CWE-863 |
| Reported | 2026-06-05 |
| Disclosed | 2026-09-21 |
| Status | Published |
The Events Calendar fails to perform proper per-object authorization checks on a family of REST API write routes. An authenticated user with a low-privilege role such as Contributor can modify, unpublish, trash, and take ownership of events, venues, and organizers belonging to other users, including administrators.
Impact
A successful exploitation allows an authenticated Contributor-level attacker to alter or remove event-related content owned by other users and potentially take ownership of those records. This breaks intended WordPress object-level access controls and can result in unauthorized modification, unpublishing, deletion, or ownership changes to Events, Venues, and Organizers.