haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-133905.3medium[patched]

Unauthenticated Event Aggregator Import Status Manipulation

TARGET ECOSYSTEM / VENDORThe Events Calendar
AFFECTED PRODUCTThe Events Calendar (< 6.16.5.1)
CWE CLASSIFICATIONCWE-284: Improper Access Control
PUBLISHED DATE2026-07-06

Summary

The Events Calendar (< 6.16.5.1) does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and store arbitrary content in a hidden comment record.