The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API
2026-02-25 08:50
type5afeStrategic Overview
StatusPatched in 6.15.16.1
Affected PluginThe Events Calendar
Affected Version
<= 6.15.16CVSS5.4Medium
CVE
CVE-2026-2694Vulnerability Overview
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.
Technical Analysis
REMEDIATION: Update to version 6.15.16.1, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C