Description
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Published: 2026-08-28
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to protected event management functions
Action: Patch
AI Analysis

Impact

The flaw is a broken access control in the WordPress WpEvently plugin, version 5.5.0 and earlier. Because the plugin does not enforce proper authorization before allowing certain administrative or event‑creation operations, an attacker who can access the web interface can elevate privileges or perform unauthorized actions. This vulnerability is classified as CWE‑862.

Affected Systems

Any WordPress site that uses the Magepeople Inc. WpEvently plugin version 5.5.0 or older remains vulnerable until the plugin is upgraded beyond 5.5.0. The vulnerability does not affect other components of WordPress outside the plugin.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the lack of an EPSS score and omission from the CISA KEV catalog suggest that widespread exploitation is not yet documented. The likely attack vector is the web interface, where attackers can target administrative endpoints that fail to enforce proper permission checks. If exploited, an attacker could gain unauthorized control over event creation, modification, or deletion, compromising the integrity and confidentiality of the site’s event data.

Generated by OpenCVE AI on August 28, 2026 at 16:44 UTC.

Remediation

Vendor Solution

Update the WordPress WpEvently Plugin to the latest available version (at least 5.6.0).


OpenCVE Recommended Actions

  • Update the WordPress WpEvently Plugin to version 5.6.0 or later.
  • If an update cannot be performed immediately, deactivate and remove the plugin to eliminate the risk surface.
  • Verify that all event‑related pages and administrative functions enforce correct role‑based access controls before reinstating the plugin or related functionalities.

Generated by OpenCVE AI on August 28, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Magepeopleteam
Magepeopleteam wpevently
Wordpress
Wordpress wordpress
Vendors & Products Magepeopleteam
Magepeopleteam wpevently
Wordpress
Wordpress wordpress

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Title WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Magepeopleteam Wpevently
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-28T16:08:16.510Z

Reserved: 2026-08-27T12:22:09.412Z

Link: CVE-2026-81759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:30.210

Modified: 2026-08-28T20:20:12.730

Link: CVE-2026-81759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T12:45:12Z

Weaknesses