Impact
A missing authorization flaw in the EventON eventon-lite plugin for WordPress allows unauthenticated users to access features that should be protected by access control lists. Based on the description, it is inferred that an attacker could exploit the flaw by sending unauthenticated requests to the plugin’s endpoints. The vulnerability exposes sensitive functionality to anyone who can reach the plugin’s endpoints, potentially revealing event data, administrative settings, or other privileged information. It is classified as CWE-862, meaning the software fails to enforce proper permissions on operations it performs.
Affected Systems
The flaw affects the EventON plugin by Ashan Perera for all releases up to and including version 2.4.4. Any WordPress site that has installed this plugin in those versions is vulnerable, regardless of the site’s broader access control configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, balancing the risk of unauthorized access against the complexity of exploitation. Based on the description, the likely attack vector is accessing an unprotected endpoint within the plugin, a task that is likely trivial for anyone who can contact the site. The EPSS score of less than 1% signifies that, while the vulnerability exists, exploitation is currently considered unlikely or rare. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely targeted in the wild.
OpenCVE Enrichment
EUVD