Impact
The vulnerability in the WP Event Solution plugin allows an attacker to delete arbitrary content from a WordPress site. Exploiting this flaw could result in loss of posts, pages, or other custom content, undermining the integrity and availability of the site’s data. The weakness is classified as CWE‑862 (Missing Authorization).
Affected Systems
This issue affects installations of the Arraytics WP Event Solution plugin version 4.1.19 and earlier. Any WordPress site that has not updated beyond version 4.1.19 is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web‑based request sent by a user with administrative or sufficient privileges to the plugin’s deletion functionality. The attack requires the attacker to provide valid authentication credentials or exploit an existing administrative session.
OpenCVE Enrichment