Impact
The vulnerability is a missing authorization flaw in the WpEvently WordPress plugin that allows attackers to exploit incorrectly configured access control levels. By passing through the plugin’s security checks, an attacker can access or manipulate functions normally restricted to privileged users. This can lead to unauthorized reading, modification, or deletion of event data, potentially exposing sensitive information or disrupting site functionality.
Affected Systems
The affected product is the WpEvently plugin developed by MagePeopleTeam, versions from the first release through 4.2.9 inclusive.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, the attack vector is remote, via HTTP requests to the plugin’s endpoints, and does not appear to require prior authentication. The risk to a site that has not applied the fix is moderate but could be amplified if the plugin is exposed to public users. Adopting the official fix or tighter controls is advised.
OpenCVE Enrichment
EUVD