WordPress Plugin Vulnerabilities

The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes

Description

The plugin does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.

Proof of Concept

Affects Plugins

Fixed in 6.17.5

References

Classification

Type
INCORRECT AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Mohammed Abd Alrahman
Submitter
Mohammed Abd Alrahman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 1 day ago)
Added
2026-09-21 (about 17 hours ago)
Last Updated
2026-09-21 (about 17 hours ago)

Other