Description
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them.
Problem types
Product status
* (semver)
Timeline
| 2025-10-24: | Vendor Notified |
| 2025-10-30: | Disclosed |
Credits
Md. Moniruzzaman Prodhan
References
www.wordfence.com/...-80e0-42c7-981c-dea3a18cf4d5?source=cve
github.com/...s-calendar/blob/main/src/Events/QR/QR_Code.php
plugins.trac.wordpress.org/...5.10/src/Events/QR/QR_Code.php