← Back to CVE Registry
CVE-2026-133905.3medium[patched]
Unauthenticated Event Aggregator Import Status Manipulation
TARGET ECOSYSTEM / VENDORThe Events Calendar
AFFECTED PRODUCTThe Events Calendar (< 6.16.5.1)
CWE CLASSIFICATIONCWE-284: Improper Access Control
PUBLISHED DATE2026-07-06
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
The Events Calendar (< 6.16.5.1) does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and store arbitrary content in a hidden comment record.