Impact
The vulnerability allows an attacker to bypass authentication controls in the WordPress WP Event SOlution plugin version 4.1.9 or earlier, enabling unauthorized access to privileged functions. The flaw originates from improper handling of authentication tokens, leading to a weakness classified as CWE-288. An attacker could exploit this to gain administrative privileges within the plugin, potentially escalating privileges to broader WordPress site control.
Affected Systems
The flaw affects the Arraytics WP Event SOlution product for WordPress. Users running any version of the plugin 4.1.9 or earlier are susceptible. The vendor advisory specifies that all releases prior to 4.1.10 contain the issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Because the EPSS score is not available, the likelihood of exploitation cannot be determined from the data, but the absence of a KEV listing suggests no confirmed exploitation in the wild. Unauthenticated attackers can potentially exploit the flaw by sending crafted requests to the plugin’s authentication endpoints, so the attack vector is likely Remote.
OpenCVE Enrichment