Impact
The vulnerability allows an unauthenticated user to bypass access control checks in the Quick Event Manager WordPress plugin and perform actions reserved for authenticated or administrative users, such as creating, editing, or deleting events, and potentially viewing sensitive data. This breach of the basic principle of least privilege can lead to data tampering, unauthorized data exposure, and disruption of event management features.
Affected Systems
The affected product is Quick Event Manager from Brightvesseldev. Versions 9.17 and earlier are impacted.
Risk and Exploitability
The flaw is scored with a CVSS of 7.5, indicating high severity. No EPSS score is provided, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting limited publicly known exploitation at this time. The likely attack vector is any HTTP request to the plugin’s administrative endpoints, which an attacker can craft without authentication. Exploitation requires no special environment or privileged credentials, making the risk significant for sites still running vulnerable versions.
OpenCVE Enrichment