{"id":"CVE-2026-84743","published":"2026-09-23T06:17:03.603","lastModified":"2026-09-23T18:13:31.210","description":"The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.","cvssScore":3.8,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/6c20337d-f485-491c-a380-38a3039af17d/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}