CVE-2026-13390 PUBLISHED

The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation

Assigner: WPScan
Reserved: 26.06.2026 Published: 27.07.2026 Updated: 27.07.2026

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.

Product Status

Vendor Unknown
Product The Events Calendar
Versions Default: unaffected
  • affected from 0 to 6.16.5.1 (excl.)

Credits

  • Haitam Lazaar finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE