WordPress Plugin Vulnerabilities

The Events Calendar < 6.15.16.1 - Contributor+ Event/Organizer/Venue Update/Trash via REST API

Description

The plugin is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.

Affects Plugins

Fixed in 6.15.16.1

References

Classification

Type
INCORRECT AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
type5afe
Verified
No

Timeline

Publicly Published
2026-02-25 (about 2 months ago)
Added
2026-02-25 (about 2 months ago)
Last Updated
2026-02-25 (about 2 months ago)

Other