Impact
This vulnerability arises from missing authorization checks within the Eventer plugin, allowing an attacker to bypass intended access controls and modify event data. The issue can compromise the integrity and confidentiality of event information and is mapped to CWE‑862, representing a moderate severity risk.
Affected Systems
All installations of the WordPress Eventer plugin from imithemes running a version prior to 3.11.4 are impacted, as the vulnerability is present from n/a through < 3.11.4.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as moderate, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is via the web interface of a WordPress site, enabling a remote attacker to reach the vulnerable plugin without additional privileges. No public exploit code has been disclosed yet.
OpenCVE Enrichment
EUVD