Impact
The vulnerability in Sayful Islam’s Upcoming Events Lists plugin allows an attacker to bypass authorization by manipulating a user-controlled key, thereby accessing event data or settings that should be restricted. This IDOR flaw exposes sensitive information, highlighting a confidentiality risk.
Affected Systems
All WordPress installations using the Upcoming Events Lists plugin by Sayful Islam with versions up to and including 1.4.0 are affected. No further version restrictions are listed beyond the indicated maximum of 1.4.0.
Risk and Exploitability
Based on the description, the likely attack vector involves crafting requests to event URLs or AJAX endpoints to exploit the IDOR flaw and retrieve data belonging to other users or private events. The description indicates no specific prerequisites beyond authenticated or unauthenticated access are required, thereby making the attack feasible against exposed installations. The CVSS score of 5.4 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD