Executive brief
The Events Calendar, a popular WordPress plugin for managing event listings, contains a security flaw in its data import system. An unauthorized person can remotely interfere with active event imports, causing them to fail and injecting arbitrary text into internal logs. While this does not directly expose sensitive customer data, it can disrupt website operations and clutter administrative records with malicious content.
Technical details
The vulnerability exists in the Event Aggregator REST API route `tribe/event-aggregator/v1/import/<import_id>/state`. The plugin fails to perform an authorization check (CWE-862) and bypasses an integrity check (batch_hash validation) when the 'status' parameter is set to 'failed'. An unauthenticated attacker can send a crafted POST request to this endpoint to mark pending import records as failed. Additionally, the attacker can control the 'message' and 'message_slug' parameters, which are stored in the database as hidden comment records (`tribe-ea-error`). While the stored content is escaped in the admin interface (preventing XSS), the flaw allows for unauthorized data manipulation and denial of service for import tasks. The issue is fixed in version 6.16.5.1.
Affected products
- The Events Calendar The Events Calendar < 6.16.5.1
Timeline
- 2026-07-06: disclosed: Publicly published by WPScan
- 2026-07-27: advisory: NVD publication date