All vulnerabilities
CVE-2026-84745 Low CVSS 2.7

The Events Calendar — Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API

Vendor StellarWP (The Events Calendar)
Product The Events Calendar
Affected versions < 6.17.3.1
Weakness CWE-200
CVSS vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Reported 2026-08-12
Disclosed 2026-09-03
Status Published
The plugin fails to restrict access to non-public content on its public REST API archives, allowing users with the Contributor role or above to read the full contents of every unpublished event, venue, and organizer record on the site, including those created by other users.

Impact

A low-privileged authenticated user can enumerate and read draft/private event, venue, and organizer records belonging to other users via the REST API — an information disclosure issue that could expose unreleased event details, internal notes, or personal organizer/venue data before intended publication.