All vulnerabilities
CVE-2026-84743 Low CVSS 3.8

The Events Calendar 6.15.16.1 – 6.17.4.1 – Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes

Vendor The Events Calendar / StellarWP
Product The Events Calendar
Affected versions 6.15.16.1 – 6.17.4.1
Weakness CWE-863
Reported 2026-06-05
Disclosed 2026-09-21
Status Published
The Events Calendar fails to perform proper per-object authorization checks on a family of REST API write routes. An authenticated user with a low-privilege role such as Contributor can modify, unpublish, trash, and take ownership of events, venues, and organizers belonging to other users, including administrators.

Impact

A successful exploitation allows an authenticated Contributor-level attacker to alter or remove event-related content owned by other users and potentially take ownership of those records. This breaks intended WordPress object-level access controls and can result in unauthorized modification, unpublishing, deletion, or ownership changes to Events, Venues, and Organizers.