CVE-2026-1987
MEDIUMScheduler Widget plugin <0.1.6 - Insecure Direct Object Reference
Title source: llmDescription
The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` function lacking proper authorization checks and ownership verification when updating events. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify any event in the scheduler via the `id` parameter granted they have knowledge of the event ID.
References (6)
Core 6
Core References
Product
https://plugins.trac.wordpress.org/browser/scheduler-widget/tags/0.1.6/scheduler-widget.php#L158
Various Sources
https://cwe.mitre.org/data/definitions/639.html
Various Sources
https://cwe.mitre.org/data/definitions/862.html
Scores
CVSS v3
5.4
EPSS
0.0031
EPSS Percentile
22.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
morelmathieuj/Scheduler Widget
< 0.1.6
Published
Feb 14, 2026
Tracked Since
Feb 18, 2026