Impact
The vulnerability is a missing authorization flaw in the Fullworks Display Eventbrite Events widget-for-eventbrite-api plugin for WordPress. Because the plugin’s access control safeguards are incorrectly configured, an attacker can perform operations reserved for privileged users without proper authorization. This can lead to unauthorized modification or retrieval of event data, compromising the integrity and confidentiality of the event listings that the plugin exposes.
Affected Systems
The Fullworks Display Eventbrite Events plugin for WordPress is affected on all releases up to and including version 6.5.6. WordPress sites that have this plugin installed and running the vulnerable version are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is below 1%, suggesting a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack surface is via HTTP endpoints provided by the plugin, and the exploit can be attempted by anyone who can reach the site. Successful exploitation would grant the attacker whatever privileges they have in the WordPress environment, allowing them to modify or view event data without authorization.
OpenCVE Enrichment