Description
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.
Published: 2026-08-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Wired Impact Volunteer Management plugin lacks proper authorization checks for its AJAX action that removes RSVPs. An attacker who has authenticated with a role as low as Subscriber can delete any RSVP attached to any volunteer opportunity, causing loss of data and potential disruption to volunteer coordination. The primary impact is integrity breach of RSVP data, which could also affect availability of volunteer records.

Affected Systems

WordPress sites that run Wired Impact Volunteer Management before version 2.8.2 are affected. The vulnerability exists regardless of WordPress core version but applies solely to the plugin files that implement the wivm_remove_rsvp action.

Risk and Exploitability

No EPSS score is available and the issue is not listed in CISA KEV, indicating that there is no known exploitation activity at the time of this analysis. The attack requires the victim to be authenticated; therefore the risk is moderate, but the lack of public exploits suggests a low probability of widespread attacks. The CVSS score is not provided, so risk assessment must rely on the described impact and the fact that any authenticated user can delete arbitrary data.

Generated by OpenCVE AI on August 4, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Wired Impact Volunteer Management to version 2.8.2 or later to apply the authorization fix.
  • If an update is not immediately possible, restrict the Subscriber role so that it cannot access the AJAX endpoint or disable the wivm_remove_rsvp action entirely through code or a security plugin.
  • Monitor access logs for DELETE or AJAX requests to the wivm_remove_rsvp endpoint and investigate any unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.
Title Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T06:00:12.955Z

Reserved: 2026-07-22T10:12:29.852Z

Link: CVE-2026-16546

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:15:03Z

Weaknesses

No weakness.