CVE-2026-97285: WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
Affected Software
1 affected component
The Events Calendar The Events Calendar<=6.17.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress The Events Calendar pluginto a version that resolves this vulnerability.Fixed in 6.17.5.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using an affected version of The Events Calendar. The vector is network-accessible and does not require user interaction.
2
What is the potential impact?
The issue can affect integrity and availability, while no confidentiality impact is indicated. Exploitation could allow unauthorized actions beyond the intended Contributor permissions.