CVE-2026-84742

low

Description

The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.

References

https://wpscan.com/vulnerability/f9228a51-1293-4a96-95da-0e57b7eb5f6b/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85039

Details

Source: Mitre, NVD

Published: 2026-09-23

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 3.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 2.7

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Severity: Low

EPSS

EPSS: 0.00229