Sceawere

Vulnerability Detail

CVE-2026-84740UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

The Events Calendar Shortcode Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
16h ago
Vendor
Unknown
Product
The Events Calendar
Attack Type
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-02T07:16:38.000Z",
  "pubdate": "2026-10-02T07:16:38.000Z",
  "executiveSummary": "The Events Calendar WordPress plugin before version 6.17.5.1 contains a critical vulnerability involving improper input validation within an unauthenticated AJAX action.\nThis flaw allows remote, unauthenticated attackers to inject and execute arbitrary shortcodes on the target site.\nThe vulnerability stems from the application's failure to sanitize or validate user-supplied input before merging it into the rendering context.\nSuccessful exploitation grants attackers the ability to execute any shortcode registered on the WordPress environment, which may result in sensitive data disclosure, unauthorized content manipulation, or the triggering of malicious functionalities inherent to other installed plugins or themes.\nGiven that the exploit does not require authentication, it poses a significant risk to site integrity and security, as it can be triggered by any remote user with access to the public-facing AJAX endpoint.\nUsers are urged to update to version 6.17.5.1 or later immediately to mitigate the risk of remote code execution or secondary exploitation vectors.",
  "technicalDetails": "The vulnerability resides within an unauthenticated AJAX action provided by The Events Calendar plugin. The root cause is the lack of strict input sanitization and validation protocols applied to user-supplied parameters before those parameters are processed by the plugin's rendering engine.\nIn the WordPress environment, shortcodes are dynamic placeholders that execute server-side code when parsed by the 'do_shortcode' function or similar rendering mechanisms. Because the plugin processes user-submitted data and merges it directly into the rendering pipeline without checking for, or neutralizing, shortcode syntax, an attacker can supply a crafted payload containing arbitrary shortcodes.\nThe attack flow begins with the attacker identifying the specific AJAX endpoint exposed by the plugin. By sending a crafted HTTP POST or GET request to this endpoint, the attacker injects a shortcode string into the vulnerable input field. When the plugin handles this AJAX request, it treats the malicious input as legitimate content and renders it within the page context. Consequently, the WordPress engine executes the injected shortcode as if it were a native part of the site's content.\nThe impact of this vulnerability is broad, as it is limited only by the shortcodes currently registered on the target WordPress installation. An attacker can leverage this to display sensitive information, execute administrative actions if exposed via shortcodes, or perform other secondary attacks such as Cross-Site Scripting (XSS) if specific themes or plugins support shortcodes that output unsanitized HTML or JavaScript. The attack is fully unauthenticated, requiring no prior knowledge of the site's credentials or administrative access.\nAffected versions include all versions of The Events Calendar prior to 6.17.5.1. The flaw is persistent during the request lifecycle, and because it targets the plugin's rendering logic, it can be exploited remotely over the network without any interaction from legitimate administrators.\nBy bypassing the implicit trust placed in user input, the plugin creates a bridge for unauthorized code execution. Post-exploitation impact varies depending on the functionality of the shortcodes available on the site, but generally leads to unauthorized data access and potential escalation of privileges."
}
CVE-2026-84740: The Events Calendar Shortcode Injection (MEDIUM Severity, CVSS: 6.5) | Sceawere