All vulnerabilities
CVE-2026-84745
Low
CVSS 2.7
The Events Calendar — Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API
| Vendor | StellarWP (The Events Calendar) |
|---|---|
| Product | The Events Calendar |
| Affected versions | < 6.17.3.1 |
| Weakness | CWE-200 |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
| Reported | 2026-08-12 |
| Disclosed | 2026-09-03 |
| Status | Published |
The plugin fails to restrict access to non-public content on its public REST API archives, allowing users with the Contributor role or above to read the full contents of every unpublished event, venue, and organizer record on the site, including those created by other users.
Impact
A low-privileged authenticated user can enumerate and read draft/private event, venue, and organizer records belonging to other users via the REST API — an information disclosure issue that could expose unreleased event details, internal notes, or personal organizer/venue data before intended publication.