CVE-2026-2694 PUBLISHED

The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API

Assigner: Wordfence
Reserved: 18.02.2026 Published: 25.02.2026 Updated: 25.02.2026

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 5.4

Product Status

Vendor stellarwp
Product The Events Calendar
Versions Default: unaffected
  • affected from * to 6.15.16 (incl.)

Credits

  • M Indra Purnama finder

References

Problem Types

  • CWE-285 Improper Authorization CWE