Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators. | |
| Title | The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:56:22.720Z
Reserved: 2026-09-02T08:41:21.163Z
Link: CVE-2026-84743
Updated: 2026-09-23T10:36:01.141Z
Status : Received
Published: 2026-09-23T06:17:03.603
Modified: 2026-09-23T11:17:13.670
Link: CVE-2026-84743
No data.
OpenCVE Enrichment
Updated: 2026-09-23T14:30:06Z