Impact
The Events Manager WordPress plugin fails to enforce WordPress's existing access control determinations. As a result, any unauthenticated user can target a post ID that matches a user’s ID and submit requests that change the user’s password, elevate that user to the Administrator role, or delete that account entirely. This flaw constitutes a complete privilege escalation and an account takeover for affected sites.
Affected Systems
The vulnerability affects the Events Manager plugin for WordPress in all releases prior to 7.4.1. Sites running any version of the plugin before this release, regardless of user role, are susceptible.
Risk and Exploitability
The flaw allows attackers without any credentials to gain administrator access by leveraging a simple HTTP request to the plugin’s endpoint. Because the issue stems from a flaw in capability mapping, it can be abused by any user who can send requests to the site, making it high risk. While the EPSS score is not available and the vulnerability is not yet listed in the CISA KEV catalog, the potential impact of a successful exploit is severe.
OpenCVE Enrichment