Description
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3.
Published: 2026-03-19
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Payment Bypass via Missing Authorization
Action: Apply Patch
AI Analysis

Impact

The EventPrime plugin contains a missing authorization flaw that lets an attacker complete payments without proper authentication. This flaw permits unauthorized payment actions, resulting in revenue loss, data integrity problems, and potential fraud. The weakness is rooted in an incorrectly configured access control security level and is identified as CWE‑862.

Affected Systems

The vulnerability affects the WordPress EventPrime eventcalendar‑management plugin from Metagauss. All released versions through 4.2.8.3 are susceptible. Users running any of these versions on WordPress sites must upgrade to a newer release to remove the flaw.

Risk and Exploitability

Exploit probability is indicated as less than 1%, implying a low likelihood of automated exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited current exploitation. Likely exploitation would occur through the web interface, manipulating the payment endpoint in a way that bypasses the required authorization checks. The potential impact of accepting unauthorized payments represents a serious business risk.

Generated by OpenCVE AI on April 2, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update EventPrime to a version newer than 4.2.8.3
  • If a patch cannot be applied immediately, disable or restrict payment functionality until a fix is available
  • Review and enforce proper authorization checks on all payment routes
  • Monitor payment logs and user activity for signs of unauthorized transactions

Generated by OpenCVE AI on April 2, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.2.8.3. Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 19 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Mar 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Theeventprime
Theeventprime eventprime
Wordpress
Wordpress wordpress
Vendors & Products Theeventprime
Theeventprime eventprime
Wordpress
Wordpress wordpress

Thu, 19 Mar 2026 07:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.2.8.3.
Title WordPress EventPrime plugin <= 4.2.8.3 - Payment Bypass vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Theeventprime Eventprime
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T16:00:41.918Z

Reserved: 2026-02-02T12:20:39.016Z

Link: CVE-2026-25312

cve-icon Vulnrichment

Updated: 2026-03-19T14:02:56.320Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-19T08:16:18.940

Modified: 2026-04-01T17:28:35.317

Link: CVE-2026-25312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T07:59:57Z

Weaknesses