Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.1 WordPress CVE-2026-84740

Unauthenticated Shortcode Injection Vulnerability in The Events Calendar WordPress Plugin (CVE-2026-84740)

The Events Calendar WordPress plugin, versions 6.12.0 up to but not including 6.17.5.1, contains a vulnerability that allows unauthenticated attackers to execute arbitrary shortcodes registered on a site via an unauthenticated AJAX action. No fixed version has been confirmed.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability has been disclosed in The Events Calendar, a WordPress plugin used by site owners to manage and display event listings. The issue, tracked as CVE-2026-84740, affects versions 6.12.0 up to but not including 6.17.5.1 and allows unauthenticated users to execute shortcodes registered on the affected site. This briefing summarizes what is currently known based on the available advisory data.

What Happened

A vulnerability was disclosed affecting The Events Calendar WordPress plugin. The flaw allows unauthenticated users to execute arbitrary shortcodes that are registered on the site. This is possible through an unauthenticated AJAX action that does not validate or sanitize submitted data before it is merged into the plugin's rendering context.

Technical Cause

The root cause is classified under CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component, also known as Injection). Specifically, data submitted to an unauthenticated AJAX action is not validated or sanitized before being merged into the plugin's rendering context. Because the AJAX action does not require authentication, an attacker with no account on the site can supply input that causes arbitrary shortcodes registered on the site to be executed.

Why It Matters

Shortcode injection can allow an attacker to trigger functionality exposed through any shortcode registered by the site, including those added by other plugins or themes, potentially leading to a range of downstream effects depending on what shortcodes are available. Because the vulnerability requires no authentication and no user interaction, it can be triggered directly by a remote attacker against any exposed, affected site.

Affected Versions

The Events Calendar plugin versions from 6.12.0 up to (but not including) 6.17.5.1 are affected.

Fixes and Mitigation

The fact package indicates that no fix is currently confirmed as available for this vulnerability (fix_available: false). Site owners should monitor the vendor's official plugin page and changelog for an update addressing CVE-2026-84740. Until a confirmed fix is released, consider restricting access to AJAX endpoints where feasible or using a web application firewall as a temporary compensating control.

Recommended Action

Site administrators running The Events Calendar plugin should verify their installed version against the affected range (6.12.0 up to, but not including, 6.17.5.1). Because no fix version is confirmed in the available data, check the plugin's official changelog directly for updates addressing this issue, and apply any available update as soon as it is released.

PatchBriefing score

5.1 / 10 · Medium

Official CVSS: 6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Why this score

This vulnerability has a Patchwire score of 5.1, reflecting a CVSS base score of 6.5 (CVSS:3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) weighted by several additional factors: the vulnerability can be exploited remotely without authentication, requires no user interaction, and currently has no confirmed fix available, all of which increase the score contribution. There is no evidence of known exploitation or public exploit code, and no EPSS score is available, which limits the overall score compared to actively exploited issues. The plugin's substantial install base was also factored in as a measure of potential exposure.

Affected versions

The Events Calendar ≥ 6.12.0 < 6.17.5.1
vulnerable

Reported fixes

The fact package indicates that no fix is currently confirmed as available for this vulnerability (fix_available: false). Site owners should monitor the vendor's official plugin page and changelog for an update addressing CVE-2026-84740. Until a confirmed fix is released, consider restricting access to AJAX endpoints where feasible or using a web application firewall as a temporary compensating control.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
Unified report
Unauthenticated Shortcode Injection Vulnerability in The Events Calendar WordPress Plugin (CVE-2026-84740)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email