Impact
The vulnerability is a missing authorization flaw that allows an attacker to change plugin settings within WordPress Event Espresso 4 Decaf. The flaw is based on incorrectly configured access control security levels, enabling an unauthenticated or low‑privilege user to perform privileged actions. The impact is that an attacker could alter configuration options, potentially compromising site functionality or enabling further attacks.
Affected Systems
Affected by Event Espresso:Event Espresso 4 Decaf for versions from n/a through ≤ 5.0.37.decaf. Any installation of the plugin on WordPress that falls within this version range is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1 % suggests a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV. Based on the description the likely attack vector is a web‑based request to the plugin’s settings endpoint, and the exploitation requires the attacker to be authenticated with a role that is incorrectly granted permission to change settings. Because the flaw is an authorization bypass (CWE‑862), attackers who can reach the plugin’s administrative interface can modify configuration data without proper checks.
OpenCVE Enrichment