Description
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WP Event Solution plugin allows an attacker to delete arbitrary content from a WordPress site. Exploiting this flaw could result in loss of posts, pages, or other custom content, undermining the integrity and availability of the site’s data. The weakness is classified as CWE‑862 (Missing Authorization).

Affected Systems

This issue affects installations of the Arraytics WP Event Solution plugin version 4.1.19 and earlier. Any WordPress site that has not updated beyond version 4.1.19 is at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web‑based request sent by a user with administrative or sufficient privileges to the plugin’s deletion functionality. The attack requires the attacker to provide valid authentication credentials or exploit an existing administrative session.

Generated by OpenCVE AI on August 13, 2026 at 16:00 UTC.

Remediation

Vendor Solution

Update the WordPress Eventin plugin to the latest available version (at least 4.1.20).


OpenCVE Recommended Actions

  • Update the WP Event Solution plugin to version 4.1.20 or newer as provided by Arraytics.
  • If an update cannot be applied immediately, disable the WP Event Solution plugin to prevent further content deletions.
  • Restore any accidentally deleted content from recent backups and verify restored data integrity.

Generated by OpenCVE AI on August 13, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Arraytics
Arraytics wp Event Solution
Wordpress
Wordpress wordpress
Vendors & Products Arraytics
Arraytics wp Event Solution
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
Title WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Arraytics Wp Event Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:48:23.293Z

Reserved: 2026-02-25T12:14:40.738Z

Link: CVE-2026-28173

cve-icon Vulnrichment

Updated: 2026-08-13T14:25:12.188Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:59.277

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:45:04Z

Weaknesses