What is CVE-2026-13390?
CVE-2026-13390 involves a missing authorization check in an Event Aggregator REST API route of The Events Calendar WordPress plugin, which also skips an integrity check. This allows unauthenticated attackers to mark import records as failed and store arbitrary data. Updating the plugin to version 6.16.5.1 is recommended.
Azərbaycanca: CVE-2026-13390, Events Calendar WordPress plaginində avtorizasiya yoxlanışı olmayan REST API marşrutu ilə bağlıdır. Bu zəiflik autentifikasiya olunmamış hücumçulara idxal qeydlərini uğursuz kimi qeyd etməyə və arbitrari məlumat saxlamağa imkan verir. Plaginin 6.16.5.1 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which component of The Events Calendar plugin was CVE-2026-13390 discovered?
This vulnerability involves a missing authorization check in an Event Aggregator REST API route.
To which version should The Events Calendar plugin be updated to mitigate CVE-2026-13390?
Updating the plugin to version 6.16.5.1 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.