Vulnerability in The Events Calendar — CVE-2026-97285
MediumSeverity
—Estimated exploit probability
600,000+ sitesInstalls
6.17.5.1Fixed in
What to do now
Update The Events Calendar to 6.17.5.1 or later.
Affected versions
- Everything up to and including 6.17.5
Affected: The Events Calendar (plugin, the-events-calendar)
What the vulnerability is
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.17.5. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.