Impact
A missing authorization check in the EventON WordPress plugin allows an attacker to exploit incorrectly configured access control levels and gain unauthorized access to event management functionality. The flaw, cataloged as CWE-862, enables potential data disclosure and manipulation of event information by users without proper privileges.
Affected Systems
The vulnerability affects all installations of the ashanjay EventON plugin through version 4.9.9, which is a WordPress event calendar plugin used for managing event lists and registrations.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity issue, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers would need to be able to send crafted requests to the plugin’s endpoints without the necessary authorization checks, so while the risk is moderate, the impact could be significant if sufficient privileges are granted.
OpenCVE Enrichment
EUVD