Impact
The vulnerability is an unauthenticated Insecure Direct Object Reference in the WordPress WpEvently Plugin, allowing an attacker to manipulate URL or request parameters that reference event identifiers. This flaw can enable an attacker to view, edit, or delete event information without authentication, compromising the confidentiality and integrity of event data. The weakness is categorized as CWE‑639, which is a typical IDOR scenario where access permissions are not enforced correctly.
Affected Systems
The affected product is the WordPress WpEvently Plugin from Magepeople Inc. Versions 5.6.0 and earlier are impacted. The specific version range is not further split; any release at or below 5.6.0 lacks the required protection. Users running these versions should verify their installation and ensure they are not using any compromised configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, so the current exploitation probability is uncertain, but the existence of an IDOR flaw and the lack of authentication requirements mean the vector is likely a normal web request, and attack is feasible from any network. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw without needing elevated privileges, making it a credible risk for sites that expose event data publicly.
OpenCVE Enrichment