Impact
The Events Manager plugin for WordPress lacks proper authorization checks on all versions up to 7.4.0. Recipients who are not authenticated can retrieve titles, dates, descriptions, and location details of events and venues that administrators have marked as draft, pending, trashed, or private. This results in exposure of sensitive or confidential information to unauthenticated users, exposing administrative planning and potential personal data to threat actors.
Affected Systems
Netweblogic’s Events Manager – Calendar, Bookings, Tickets and more! plugin is vulnerable in all releases up to and including 7.4.0. Users running these versions should verify the installed revision; upgrading to 7.4.1 or later eliminates the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium impact. The EPSS score is not available, suggesting a lack of recent exploitation data, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve direct HTTP requests to the plugin’s event retrieval endpoints, where the absence of authorization checks permits unauthorized data disclosure.
OpenCVE Enrichment