Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.5 WordPress CVE-2026-84741 CVE-2026-97285 CVE-2026-84743 CVE-2026-84742

Four Access Control Vulnerabilities Found in The Events Calendar WordPress Plugin

The Events Calendar WordPress plugin is affected by four separate access control issues, including unauthenticated disclosure of unpublished content and contributor-level privilege escalation. No fixed version is confirmed in available records for three of the four CVEs.

AI summary

Security researchers have published four separate CVE records affecting The Events Calendar, a WordPress plugin used on a large number of sites. All four issues relate to insufficient access control in the plugin's REST API, but they differ in severity, required privileges, and impact. This briefing summarizes what is known from the available advisory data for each of the four CVEs: CVE-2026-84741, CVE-2026-84742, CVE-2026-84743, and CVE-2026-97285.

What Happened

Four distinct vulnerabilities were disclosed in The Events Calendar WordPress plugin, all involving access control weaknesses in its REST API: - CVE-2026-84741: The plugin fails to check the post status of linked records before embedding their stored details into a public REST API response. This allows unauthenticated users to read the contents of records that have never been published. - CVE-2026-84742: The plugin does not check the capability required to publish content before creating or updating it through its REST API. Users with a role that cannot normally publish, such as Contributor, can publish content directly and bypass editorial review. - CVE-2026-84743: The plugin does not perform a per-object capability check on one family of its REST write routes. This allows users with a low-privilege role such as Contributor to modify, unpublish, trash, and take ownership of records belonging to other users, including administrators. - CVE-2026-97285: Described in the available record as "Contributor Broken Access Control." The advisory does not provide further technical detail beyond this classification.

Technical Cause

Three of the four issues (CVE-2026-84741, CVE-2026-84742, CVE-2026-84743) stem from missing or incomplete capability and status checks in the plugin's REST API endpoints, classified under CWE-200 (Information Exposure) and CWE-863 (Incorrect Authorization). CVE-2026-97285 is classified under CWE-862 (Missing Authorization), but the fact package does not include further technical detail on the specific mechanism beyond the title classification "Contributor Broken Access Control."

Why It Matters

These vulnerabilities range in impact from unauthenticated information disclosure to privilege escalation within the WordPress role system. CVE-2026-84741 is the most broadly exploitable, as it requires no authentication at all and could expose unpublished content such as draft events or internal records to any visitor. The other three issues require an authenticated Contributor-level (or similar low-privilege) account, which limits exposure to sites that allow such user registration or have compromised low-privilege accounts, but still represent a meaningful breakdown of WordPress's editorial and ownership controls.

Who Is Affected

Sites running The Events Calendar WordPress plugin within the affected version ranges are impacted. CVE-2026-84741 affects versions from 4.5 up to (but not including) 6.17.5. CVE-2026-84742 affects versions from 6.15.0 up to (but not including) 6.17.5. CVE-2026-84743 affects versions from 6.15.16.1 up to (but not including) 6.17.5. CVE-2026-97285 affects versions up to (but not including) 6.17.5.1; no introduced version is specified in the available data for this CVE.

Affected Versions

- CVE-2026-84741: The Events Calendar >= 4.5, < 6.17.5 - CVE-2026-84742: The Events Calendar >= 6.15.0, < 6.17.5 - CVE-2026-84743: The Events Calendar >= 6.15.16.1, < 6.17.5 - CVE-2026-97285: The Events Calendar < 6.17.5.1

Fixes and Mitigation

The available fact package marks fix_available as false for all four CVEs. The version ranges indicate that versions 6.17.5 and 6.17.5.1 are referenced as boundaries where the respective issues no longer apply, but the data does not confirm that a vendor-released patch resolving each CVE is confirmed available. Site owners should treat this as unresolved pending further confirmation and monitor the vendor's official changelog directly rather than relying solely on this briefing for patch confirmation.

Recommended Action

Site administrators running The Events Calendar should review their installed version against the ranges listed above. Given that fix availability is not confirmed in the data reviewed, administrators should check the plugin's official WordPress.org page and changelog directly for update guidance, restrict Contributor-level account creation where not strictly needed, and audit recently modified or published content for unexpected changes, particularly on sites that allow open user registration.

PatchBriefing score

4.5 / 10 · Medium

Official CVSS: 5.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Why this score

Each CVE carries a distinct score reflecting its specific attack requirements and impact. CVE-2026-84741 scores 5.3 (CVSS 3.1), reflecting unauthenticated network access with low confidentiality impact only. CVE-2026-97285 scores 5.4, reflecting a Contributor-level broken access control issue with low confidentiality and low availability impact. CVE-2026-84743 scores 3.8, reflecting a Contributor-level integrity and availability impact on records belonging to other users. CVE-2026-84742 scores 2.7, the lowest of the four, reflecting a lower-impact bypass of editorial publish controls. Patchwire scores (ranging from 2.4 to 4.5) incorporate these CVSS bases along with factors such as unauthenticated remote access, lack of required user interaction, absence of a confirmed fix, and the plugin's high install base, but do not reflect any known exploitation or public exploit code, as none has been reported for any of these four issues.

Affected versions

The Events Calendar ≥ 4.5 < 6.17.5
vulnerable
The Events Calendar < 6.17.5.1
vulnerable
The Events Calendar ≥ 6.15.16.1 < 6.17.5
vulnerable
The Events Calendar ≥ 6.15.0 < 6.17.5
vulnerable

Reported fixes

The available fact package marks fix_available as false for all four CVEs. The version ranges indicate that versions 6.17.5 and 6.17.5.1 are referenced as boundaries where the respective issues no longer apply, but the data does not confirm that a vendor-released patch resolving each CVE is confirmed available. Site owners should treat this as unresolved pending further confirmation and monitor the vendor's official changelog directly rather than relying solely on this briefing for patch confirmation.

How this was built

8 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
Unified report
Four Access Control Vulnerabilities Found in The Events Calendar WordPress Plugin
1 article · 8 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email