Impact
The flaw lies in the WpEvently plugin’s permission checks for subscriber accounts. A subscriber can invoke actions that should be reserved for higher‑privileged users, such as modifying event registrations or accessing data stored for other subscribers. This leads to potential confidentiality or integrity violations within the event management subsystem of a WordPress site.
Affected Systems
WordPress sites that have installed Magepeople’s WpEvently plugin version 5.5.0 or earlier are affected. The vulnerability exists in the package distributed through WordPress.org and applies to all WordPress installations that have not upgraded beyond 5.5.0.
Risk and Exploitability
The CVSS score of 4.3 classifies this as a medium‑severity vulnerability, while the EPSS score is not available and the issue is not listed in the CISA KEV catalog. This indicates that no widespread public exploits are known. The weakness can only be abused by users who are authenticated as a subscriber; thereby, the attack requires existence of a subscriber account and the attacker must be able to trigger the relevant plugin functions. As a result, the risk remains at the defined medium level pending broader evidence.
OpenCVE Enrichment