Description
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Broken Access Control in the WordPress Events Made Easy plugin up to version 3.1.3 allows attackers to bypass authentication checks and access privileged functions normally reserved for authorized users. The flaw, identified as CWE-862, can enable unauthorized configuration changes or data extraction from within the plugin. The impact is a risk of confidentiality and integrity violations due to elevated privileges.

Affected Systems

WordPress sites that have installed the Events Made Easy plugin version 3.1.3 or earlier, provided by the vendor Franky:Events Made Easy, are affected. Sites using later versions are not vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of < 1% suggests a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely through unauthenticated HTTP requests to the plugin’s administrative endpoints and can be exploited by any internet user with access to the affected WordPress site.

Generated by OpenCVE AI on August 3, 2026 at 17:33 UTC.

Remediation

Vendor Solution

Update the WordPress Events Made Easy Plugin to the latest available version (at least 3.1.4).


OpenCVE Recommended Actions

  • Update the WordPress Events Made Easy Plugin to at least version 3.1.4. The official CNA recommends applying this patch to remediate the broken access control.
  • If an immediate update is not possible, temporarily disable the Events Made Easy plugin or remove its administrative capabilities to prevent unauthenticated exploitation.
  • Implement a web application firewall rule that blocks unauthenticated requests to the plugin’s admin URLs until the patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Franky
Franky events Made Easy
Wordpress
Wordpress wordpress
Vendors & Products Franky
Franky events Made Easy
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Title WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Franky Events Made Easy
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:56:59.308Z

Reserved: 2026-07-05T21:28:04.587Z

Link: CVE-2026-59557

cve-icon Vulnrichment

Updated: 2026-07-27T14:56:55.351Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:05.750

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses