Description
Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventON: from n/a through <= 4.9.9.
Published: 2025-07-04
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the EventON WordPress plugin allows an attacker to exploit incorrectly configured access control levels and gain unauthorized access to event management functionality. The flaw, cataloged as CWE-862, enables potential data disclosure and manipulation of event information by users without proper privileges.

Affected Systems

The vulnerability affects all installations of the ashanjay EventON plugin through version 4.9.9, which is a WordPress event calendar plugin used for managing event lists and registrations.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity issue, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers would need to be able to send crafted requests to the plugin’s endpoints without the necessary authorization checks, so while the risk is moderate, the impact could be significant if sufficient privileges are granted.

Generated by OpenCVE AI on April 30, 2026 at 09:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the EventON plugin to version 4.10 or newer to receive the vendor‑supplied fix.
  • Verify that the plugin’s settings restrict event editing to users with Editor or Administrator roles, ensuring no public or unauthorized editing is possible.
  • If a patch cannot be applied immediately, block public access to the EventON event‑editing endpoints (e.g., /eventon/admin/*) using a firewall rule or URL rewriting so that only authenticated administrators can reach them.

Generated by OpenCVE AI on April 30, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19980 Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9. Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventON: from n/a through <= 4.9.9.
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Tue, 08 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9.
Title WordPress EventON plugin <= 4.9.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:45.114Z

Reserved: 2025-05-07T09:40:07.681Z

Link: CVE-2025-47565

cve-icon Vulnrichment

Updated: 2025-07-08T13:58:33.840Z

cve-icon NVD

Status : Deferred

Published: 2025-07-04T12:15:28.720

Modified: 2026-04-23T15:30:29.883

Link: CVE-2025-47565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:00:16Z

Weaknesses