What the vulnerability does
01Description
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.
Explanation of Vulnerability in Simple Terms
02Summary
The Events Calendar through version 6.15.16 contains an integrity and availability vulnerability affecting authenticated users. An attacker with low-level access can modify event data or degrade system performance. The vulnerability requires network access and valid login credentials but no additional user interaction.
What an attacker can do
03Attacker Capabilities
Modify event data or cause the site to become slow or unresponsive.
Potential impact on your site
04Site Impact
Event information could be altered by unauthorized users, or the site could experience performance degradation.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level permissions on the site.
Key dates
06Disclosure timeline
February 25, 2026
CVE published
April 8, 2026
Record updated