Back to overview

CVE-2026-13390

Description
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.

Metadata

CVE ID
CVE-2026-13390
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-26 07:17 UTC
Published
2026-07-27 06:00 UTC
Last updated
2026-07-27 06:00 UTC
Vendor / Product
Unknown / The Events Calendar
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown The Events Calendar 0 < 6.16.5.1
Weakness (CWE)
CWESourceDescription
cna CWE-862 Missing Authorization
Back to overview