Impact
The vulnerability is a missing authorization flaw in StellarWP The Events Calendar that allows an attacker to exploit improperly configured access control levels. It can lead to unauthorized manipulation or retrieval of calendar events and other configuration data, compromising the integrity and confidentiality of the application.
Affected Systems
All installations of The Events Calendar plugin from StellarWP running versions up to and including 6.15.12.2 are affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level, while the EPSS score of less than 1% points to a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a local or authenticated user who has access to the WordPress administration interface similar to any user with incorrectly scoped permissions. Exploitation would require the attacker to access the plugin’s administrative pages or APIs; no external remote exploit path is documented.
OpenCVE Enrichment