Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84740 | 1 Wordpress-extensions | 1 The Events Calendar | 2026-10-04 | 6.5 Medium |
| The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | ||||
| CVE-2026-84741 | 1 Wordpress-extensions | 1 The Events Calendar | 2026-09-28 | 5.3 Medium |
| The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published. | ||||
| CVE-2026-84742 | 1 Wordpress-extensions | 1 The Events Calendar | 2026-09-28 | 2.7 Low |
| The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review. | ||||
| CVE-2026-84743 | 1 Wordpress-extensions | 1 The Events Calendar | 2026-09-28 | 3.8 Low |
| The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators. | ||||
Page 1 of 1.