CVE WATCH / VULNERABILITY DETAIL

CVE-2026-84740

MEDIUMCVSS 6.5NVD feed

Published 2 October 2026 · tracked since 2 October 2026

Description

The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-84740 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-84740

MEDIUMCVSS 6.5NVD feed

Published 2 October 2026 · tracked since 2 October 2026

Description

The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]