Impact
The Event post plugin for WordPress versions up to 6.0.1 contains a flaw that allows an unauthenticated user to bypass the plugin’s normal permission checks. Because the plugin handles event-related data, this broken access control could let attackers perform actions that should be restricted, potentially compromising the integrity and availability of event content. The vulnerability is identified as CWE‑862, which represents a missing or incomplete authorization control.
Affected Systems
Any WordPress site that has the Bastien Ho Event post plugin installed at version 6.0.1 or earlier is vulnerable. No other WordPress components are mentioned as affected, so the issue is confined to this plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can claim the necessary privileges via the plugin’s web interface without authenticating, meaning the flaw is reachable to anyone who can access the site.
OpenCVE Enrichment