WordPress Plugin Vulnerabilities

The Events Calendar < 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API

Description

The plugin does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.

Proof of Concept

Affects Plugins

Fixed in 6.17.3.1

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Mohammed Abd Alrahman
Submitter
Mohammed Abd Alrahman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 2 days ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other