Junglewise Threat Intelligence

CVE-2026-84741: The Events Calendar REST API information disclosure

CVE-2026-84741 · Severity: medium · CVSS 5.3 · Published 2026-09-23

Executive brief

The Events Calendar WordPress plugin improperly exposes unpublished venue and organizer records through its REST API without checking access permissions. An attacker can read the full details of records that site administrators never intended to publish, potentially exposing sensitive business or contact information. The vulnerability affects all unauthenticated users and requires no special setup or interaction.

Technical details

The plugin fails to validate the post status of linked venue and organizer records before including them in REST API responses, violating the principle of least privilege for API access. This is a Sensitive Data Exposure vulnerability (CWE-200) accessible over the network to unauthenticated attackers with no preconditions. Version 6.17.5 patches the issue by implementing post status checks.

Affected products

  • Modern Tribe The Events Calendar 4.5 to 6.17.4.1

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: version 6.17.5

References