Impact
The Event List plugin for WordPress is vulnerable due to a lack of capability validation in the el_update_profile() function. Authenticated users with Subscriber-level access or higher can modify their role to Administrator, giving them full administrative control over the site, including installing plugins, altering settings, and accessing sensitive data.
Affected Systems
The flaw affects every WordPress site that has Event List version 2.0.4 or earlier installed by ovatheme.com. Any account that can log in as a Subscriber or higher is a potential target for privilege escalation.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity. The EPSS score of less than 1% suggests exploitation is unlikely in the near term, and the flaw is not yet listed in CISA KEV. Because the attack requires only a normal profile update by an authenticated user, the exploitation path is straightforward for those who can log in.
OpenCVE Enrichment
EUVD