The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce verification despite a nonce being created. This makes it possible for unauthenticated attackers to upload image files to the WordPress uploads directory and create Media Library attachments via the ep_upload_file_media endpoint.

Project Subscriptions

Vendors Products
Metagauss Subscribe
Eventprime – Events Calendar, Bookings And Tickets Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss eventprime – Events Calendar, Bookings And Tickets
Wordpress
Wordpress wordpress
Vendors & Products Metagauss
Metagauss eventprime – Events Calendar, Bookings And Tickets
Wordpress
Wordpress wordpress

Tue, 17 Feb 2026 05:45:00 +0000

Type Values Removed Values Added
Description The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce verification despite a nonce being created. This makes it possible for unauthenticated attackers to upload image files to the WordPress uploads directory and create Media Library attachments via the ep_upload_file_media endpoint.
Title EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-02-17T14:33:56.486Z

Reserved: 2026-01-29T20:00:13.921Z

Link: CVE-2026-1657

cve-icon Vulnrichment

Updated: 2026-02-17T14:33:50.892Z

cve-icon NVD

Status : Received

Published: 2026-02-17T06:16:18.173

Modified: 2026-02-17T06:16:18.173

Link: CVE-2026-1657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-17T08:48:51Z

Weaknesses