Impact
The vulnerability allows an unauthenticated user to bypass built‑in access checks in the WP Event Solution plugin. This broken access control can enable an attacker to view, modify, or delete event data and potentially access administrative functions that should be restricted. The weakness is identified as CWE‑862 and can compromise confidentiality, integrity, or availability of event information.
Affected Systems
The affected product is the WP Event Solution plugin developed by Arraytics. Versions 4.1.12 and earlier are vulnerable. Users running the WP Event Solution plugin 4.1.12 or earlier on their WordPress sites should verify their installation level.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated HTTP requests directed at the plugin’s endpoints, allowing a remote actor to exploit the missing authorization checks. The vulnerability is exploitable regardless of whether the site allows anonymous traffic, as no authentication is required to trigger the flaw.
OpenCVE Enrichment