Impact
The vulnerability is a missing authorization flaw in the RSVPMarker WordPress plugin. It allows unauthenticated or insufficiently privileged users to bypass access controls and manipulate event data or trigger actions that should be restricted to authorized administrators. The flaw may enable a range of unwanted actions, from modifying event details to potentially exposing sensitive information to other users.
Affected Systems
This flaw affects the RSVPMarker plugin for WordPress, versions from the earliest release up through 11.4.5. WordPress sites that have the plugin installed at or below these versions are vulnerable and could be compromised if an attacker gains access.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is less than 1%, implying that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the missing authorization by crafting requests to endpoints governed by the plugin. An attacker who can reach the site would likely need some form of authenticated session or could leverage social engineering to obtain credentials, although the precise attack vector is not detailed in the advisory.
OpenCVE Enrichment
EUVD