Description
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WP Event SOlution plugin allows an attacker to read commercially sensitive customer data that the plugin processes and stores. It is a classic case of sensitive data exposure, classified as CWE-201. A successful exploit could let an adversary gain knowledge of names, contact details or transaction information that should remain confidential, potentially leading to privacy violations or regulatory non‑compliance.

Affected Systems

WordPress sites that have the Arraytics WP Event SOlution plugin installed at version 4.1.18 or earlier. The fix is to upgrade to at least 4.1.19, the first version with the exposed data handling issue resolved.

Risk and Exploitability

With a CVSS score of 6.5, the flaw is moderately severe. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently being actively exploited in the wild. The attack path is likely to involve interaction with the plugin’s administrative interfaces or API endpoints; a user with sufficient privileges or an unauthenticated user with access to those endpoints could trigger the data leak. Because the flaw is a direct read of stored data, an exploit does not require additional conditions beyond accessing the plugin files or endpoints.

Generated by OpenCVE AI on August 13, 2026 at 16:31 UTC.

Remediation

Vendor Solution

Update the WordPress WP Event SOlution plugin to the latest available version (at least 4.1.19).


OpenCVE Recommended Actions

  • Update the WordPress WP Event SOlution plugin to version 4.1.19 or later.
  • If an upgrade cannot be performed immediately, disable the plugin to prevent further exposure of sensitive data.
  • Conduct an audit of all customer records stored or processed by the plugin to identify any compromised information, and take appropriate remediation such as account revocation or notification.

Generated by OpenCVE AI on August 13, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Arraytics
Arraytics wp Event Solution
Wordpress
Wordpress wordpress
Vendors & Products Arraytics
Arraytics wp Event Solution
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Title WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Arraytics Wp Event Solution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:18:37.853Z

Reserved: 2026-02-25T12:14:40.739Z

Link: CVE-2026-28174

cve-icon Vulnrichment

Updated: 2026-08-13T15:18:33.104Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:59.403

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:45:04Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data