WordPress Plugin Vulnerabilities

The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation

Description

The plugin does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.

Proof of Concept

Affects Plugins

Fixed in 6.16.5.1

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Haitam Lazaar
Submitter
Haitam Lazaar
Verified
Yes

Timeline

Publicly Published
2026-07-06 (about 21 days ago)
Added
2026-07-06 (about 20 days ago)
Last Updated
2026-07-06 (about 20 days ago)

Other