Description
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Event post plugin for WordPress versions up to 6.0.1 contains a flaw that allows an unauthenticated user to bypass the plugin’s normal permission checks. Because the plugin handles event-related data, this broken access control could let attackers perform actions that should be restricted, potentially compromising the integrity and availability of event content. The vulnerability is identified as CWE‑862, which represents a missing or incomplete authorization control.

Affected Systems

Any WordPress site that has the Bastien Ho Event post plugin installed at version 6.0.1 or earlier is vulnerable. No other WordPress components are mentioned as affected, so the issue is confined to this plugin.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate level of severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can claim the necessary privileges via the plugin’s web interface without authenticating, meaning the flaw is reachable to anyone who can access the site.

Generated by OpenCVE AI on August 3, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Event post plugin to the latest version (≥6.0.2), which includes the access control fix.
  • If an update cannot be applied immediately, disable the plugin entirely or restrict its capabilities to administrators only, for example by configuring the plugin’s settings or adding a capability filter in the theme’s functions.php file.
  • Monitor for new updates or advisories from the plugin’s repository or security advisory sites such as Patchstack, and apply any forthcoming patches as soon as they become available.

Generated by OpenCVE AI on August 3, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Bastien Ho
Bastien Ho event Post
Wordpress
Wordpress wordpress
Vendors & Products Bastien Ho
Bastien Ho event Post
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Title WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Bastien Ho Event Post
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:57:06.027Z

Reserved: 2026-07-22T08:53:35.327Z

Link: CVE-2026-65486

cve-icon Vulnrichment

Updated: 2026-07-23T15:57:01.497Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:41.713

Modified: 2026-07-23T16:17:51.210

Link: CVE-2026-65486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses