CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-13390

N/A
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-27
Last Modified2026-07-27
Data SourcesNVD

Vulnerability Description

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報