Impact
Unauthenticated Broken Access Control in the WordPress Events Made Easy plugin up to version 3.1.3 allows attackers to bypass authentication checks and access privileged functions normally reserved for authorized users. The flaw, identified as CWE-862, can enable unauthorized configuration changes or data extraction from within the plugin. The impact is a risk of confidentiality and integrity violations due to elevated privileges.
Affected Systems
WordPress sites that have installed the Events Made Easy plugin version 3.1.3 or earlier, provided by the vendor Franky:Events Made Easy, are affected. Sites using later versions are not vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of < 1% suggests a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely through unauthenticated HTTP requests to the plugin’s administrative endpoints and can be exploited by any internet user with access to the affected WordPress site.
OpenCVE Enrichment