Impact
The plugin suffers from a missing or incorrect nonce validation on the location_delete action, exposing a CSRF flaw (CWE‑352). An attacker who tricks an authenticated administrator into visiting a crafted URL can delete event locations without needing any credentials, resulting in data loss and potential disruption of event management functionality.
Affected Systems
The vulnerability affects the Events Manager – Calendar, Bookings, Tickets, and more! WordPress plugin for all versions up to and including 7.2.2.2. No other vendors or product versions are noted as impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires a social engineering click‑through; the attacker sends a forged request that bypasses the missing nonce check, resulting in authorization bypass for the delete operation. There are no indications of additional impact such as remote code execution.
OpenCVE Enrichment