Broken Access Control in The Events Calendar by Modern Tribe
CVE-2026-97285

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-97285?

The Events Calendar plugin for WordPress, developed by Modern Tribe, contains a vulnerability due to broken access control in versions up to 6.17.5. This flaw can potentially allow unauthorized users to access and manipulate calendar events, leading to exposure of sensitive information or modification of data intended for specific user groups. Maintaining proper access control is critical for safeguarding user data and ensuring the integrity of web applications. Users are strongly encouraged to update to the latest version to mitigate these risks.

Affected Version(s)

The Events Calendar <= 6.17.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erik Debye | Patchstack Bug Bounty Program
.