Description
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Published: 2026-09-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated user to bypass access control checks in the Quick Event Manager WordPress plugin and perform actions reserved for authenticated or administrative users, such as creating, editing, or deleting events, and potentially viewing sensitive data. This breach of the basic principle of least privilege can lead to data tampering, unauthorized data exposure, and disruption of event management features.

Affected Systems

The affected product is Quick Event Manager from Brightvesseldev. Versions 9.17 and earlier are impacted.

Risk and Exploitability

The flaw is scored with a CVSS of 7.5, indicating high severity. No EPSS score is provided, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting limited publicly known exploitation at this time. The likely attack vector is any HTTP request to the plugin’s administrative endpoints, which an attacker can craft without authentication. Exploitation requires no special environment or privileged credentials, making the risk significant for sites still running vulnerable versions.

Generated by OpenCVE AI on September 3, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Quick Event Manager plugin version (9.18 or later) to eliminate the access control weakness.
  • If an immediate update is not possible, temporarily block or restrict access to the plugin’s admin URLs using firewall rules or WordPress settings to prevent unauthenticated requests.
  • Re‑audit all event data created prior to the update for potential tampering or unauthorized entries, and audit access logs for suspicious activity.

Generated by OpenCVE AI on September 3, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Brightvesseldev
Brightvesseldev quick Event Manager
Wordpress
Wordpress wordpress
Vendors & Products Brightvesseldev
Brightvesseldev quick Event Manager
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Title WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Brightvesseldev Quick Event Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T16:32:00.540Z

Reserved: 2026-09-02T12:41:07.440Z

Link: CVE-2026-84847

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:29.643

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:22:34Z

Weaknesses