Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-2694

Опубликовано: 25 фев. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.

EPSS

Процентиль: 13%
0.00227
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 5.4
github
4 месяца назад

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.

EPSS

Процентиль: 13%
0.00227
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-285