Impact
Missing Authorization within the WpEvently plugin grants an attacker the ability to execute privileged functions without proper credentials. The flaw stems from incorrectly configured access control security levels, enabling users who are not intended to have certain permissions to invoke protected plugin features. If exploited, this can result in unauthorized content manipulation, data exfiltration, or additional lateral movement within the WordPress site.
Affected Systems
The WordPress plugin WpEvently by magepeopleteam, versions from the earliest released up through 5.0.4, are impacted. Site administrators should verify the installed version and upgrade if it falls within this range.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The issue is not catalogued in CISA KEV. The likely attack vector is web‑based; an adversary can send crafted requests to the plugin’s exposed endpoints to bypass normal authorization checks. Successful exploitation would typically require access to the site’s front‑end or an account with limited privileges, yet it would enable the attacker to perform functions reserved for higher‑level users.
OpenCVE Enrichment