CVE-2026-84742
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 23, 2026 · Last modified: Sep 23, 2026
Not enough EPSS history yet.
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
No related CVEs by CWE or product.