Description
Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarPress: from n/a through <= 1.33.28.
Published: 2025-10-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the WebinarPress plugin allows an attacker to access protected resources without proper verification. The flaw stems from incorrect configuration of access control security levels, classified as CWE-862. An adversary could exploit this to read or modify data intended for authorized users, potentially exposing confidential webinar content or altering scheduling data. The impact is limited to the scope of roles affected by the plugin, but can compromise all stored webinar information if elevated privileges are abused.

Affected Systems

WordPress installations running the WebinarPress plugin for WPWebinarSystem, all releases up to and including 1.33.28.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the plugin operates via the web interface, the likely attack vector is remote, but the attacker would need to target a WordPress site that has the vulnerable plugin installed and may require valid user credentials or the ability to manipulate role assignments. Availability impact is low; the issue primarily threatens confidentiality and integrity of webinar data.

Generated by OpenCVE AI on April 29, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WebinarPress to a version newer than 1.33.28 (e.g., 1.33.29 or later).
  • If upgrading is not feasible, disable or uninstall the WebinarPress plugin to eliminate the unauthorized access path.
  • Verify that role and capability settings for the plugin are correctly configured, ensuring that only appropriate user levels can access webinar management functions.

Generated by OpenCVE AI on April 29, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Tue, 03 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:webinarpress:webinarpress:*:*:*:*:lite:wordpress:*:*

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Webinarpress
Webinarpress webinarpress
Wordpress
Wordpress wordpress
Vendors & Products Webinarpress
Webinarpress webinarpress
Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarPress: from n/a through <= 1.33.28.
Title WordPress WebinarPress plugin <= 1.33.28 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Webinarpress Webinarpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:07.261Z

Reserved: 2025-10-24T14:25:07.970Z

Link: CVE-2025-62972

cve-icon Vulnrichment

Updated: 2025-10-27T15:01:58.285Z

cve-icon NVD

Status : Modified

Published: 2025-10-27T02:15:57.743

Modified: 2026-04-27T17:16:38.830

Link: CVE-2025-62972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:30:19Z

Weaknesses