{"id":"CVE-2026-84741","published":"2026-09-23T06:17:03.383","lastModified":"2026-09-23T18:13:31.210","description":"The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/0f34a90e-3d8b-4a87-a2ed-fe4d2c481732/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}