Impact
The vulnerability is a missing authorization flaw in the WooEvents plugin for WordPress. It allows users to exploit incorrectly configured access control settings, enabling actions such as creating, editing, or deleting events without proper privilege checks. The weakness is classified as CWE‑862, reflecting a failure to enforce the correct user permissions on protected resources.
Affected Systems
Ex‑Themes WooEvents plugins up through version 4.1.7 are affected. Any installation using these older versions or earlier must evaluate whether patches or upgrades have been applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, but the EPSS score of less than 1% suggests the likelihood of active exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The attack is likely remote, accessed through the WordPress web interface that hosts WooEvents, and an attacker would need to use a user account with some authenticated role to perform the restricted actions.
OpenCVE Enrichment
EUVD