Impact
The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control levels within the plugin. This can enable an unauthenticated or low‑privileged user to gain unauthorized access to privileged actions, potentially manipulating event data or executing administrative functions. The weakness is classified as CWE‑862.
Affected Systems
WordPress plugin StellarWP The Events Calendar is affected. All releases up to and including version 6.11.2.1 are vulnerable, regardless of the WordPress installation version. Site administrators should verify the installed plugin version and ensure it is not part of the affected range.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s web interface, requiring the broadcaster to misconfigure or enable administrative controls that bypass normal role checks. Exact exploitation details are not provided, so the risk is inferred from the missing authorization nature of the flaw.
OpenCVE Enrichment
EUVD