Impact
The flaw is a broken access control in the WordPress WpEvently plugin, version 5.5.0 and earlier. Because the plugin does not enforce proper authorization before allowing certain administrative or event‑creation operations, an attacker who can access the web interface can elevate privileges or perform unauthorized actions. This vulnerability is classified as CWE‑862.
Affected Systems
Any WordPress site that uses the Magepeople Inc. WpEvently plugin version 5.5.0 or older remains vulnerable until the plugin is upgraded beyond 5.5.0. The vulnerability does not affect other components of WordPress outside the plugin.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the lack of an EPSS score and omission from the CISA KEV catalog suggest that widespread exploitation is not yet documented. The likely attack vector is the web interface, where attackers can target administrative endpoints that fail to enforce proper permission checks. If exploited, an attacker could gain unauthorized control over event creation, modification, or deletion, compromising the integrity and confidentiality of the site’s event data.
OpenCVE Enrichment