Description
The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their capabilities to those of an administrator.
Published: 2025-08-26
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Event List plugin for WordPress is vulnerable due to a lack of capability validation in the el_update_profile() function. Authenticated users with Subscriber-level access or higher can modify their role to Administrator, giving them full administrative control over the site, including installing plugins, altering settings, and accessing sensitive data.

Affected Systems

The flaw affects every WordPress site that has Event List version 2.0.4 or earlier installed by ovatheme.com. Any account that can log in as a Subscriber or higher is a potential target for privilege escalation.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is considered high severity. The EPSS score of less than 1% suggests exploitation is unlikely in the near term, and the flaw is not yet listed in CISA KEV. Because the attack requires only a normal profile update by an authenticated user, the exploitation path is straightforward for those who can log in.

Generated by OpenCVE AI on April 22, 2026 at 04:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Event List to a version newer than 2.0.4 or apply the vendor’s official patch if available.
  • Restrict usage of el_update_profile() by disabling or limiting profile update features for Subscriber and lower roles until the fix is deployed.
  • If an immediate upgrade is not possible, review all Subscriber accounts and temporarily reduce their capabilities to a non-administrative role or remove them until the patch is applied, ensuring no user can elevate privileges via this path.

Generated by OpenCVE AI on April 22, 2026 at 04:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28729 The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their capabilities to those of an administrator.
History

Wed, 27 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 26 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Aug 2025 14:45:00 +0000

Type Values Removed Values Added
Description The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their capabilities to those of an administrator.
Title Event List <= 2.0.4 - Authenticated (Subscriber+) Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:54:52.168Z

Reserved: 2025-06-19T13:43:14.885Z

Link: CVE-2025-6366

cve-icon Vulnrichment

Updated: 2025-08-26T15:07:41.278Z

cve-icon NVD

Status : Deferred

Published: 2025-08-26T15:15:48.710

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-6366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T04:15:07Z

Weaknesses