Impact
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress contains a missing capability check in the booking_add_notes function, which allows authenticated attackers with Subscriber-level access and above to add arbitrary notes to the backend view of any booking. This weakness, identified as CWE-862, enables the creation of potentially misleading or fraudulent booking entries without granting broader system compromise.
Affected Systems
WordPress sites that have the EventPrime plugin installed in any version up to and including 4.2.0.0 are affected. The vulnerability applies to all installations running those versions regardless of configuration, as the check is missing in the core booking notes functionality.
Risk and Exploitability
The CVSS score of 4.3 indicates low overall severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The vulnerability can be exploited by any authenticated user with Subscriber-level or higher permissions; no additional privilege escalation is required. Based on the description, it is inferred that the attack vector is an authenticated internal user action, making it a moderate risk within an organization but unlikely to be widely abused externally.
OpenCVE Enrichment