CVE-2026-1987 PUBLISHED

Scheduler Widget <= 0.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Event Modification

Assigner: Wordfence
Reserved: 05.02.2026 Published: 14.02.2026 Updated: 14.02.2026

The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the scheduler_widget_ajax_save_event() function lacking proper authorization checks and ownership verification when updating events. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify any event in the scheduler via the id parameter granted they have knowledge of the event ID.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 5.4

Product Status

Vendor morelmathieuj
Product Scheduler Widget
Versions Default: unaffected
  • affected from * to 0.1.6 (incl.)

Credits

  • MD. TAREQ AHAMED JONY finder

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE