Impact
The vulnerability in the Events Manager WordPress plugin allows a user with contributor+ privileges to send a ticket‑update request that overwrites the identifiers of a ticket it is not authorized to modify. This results in the attacker reassignment of any ticket on the site to their own event, compromising the integrity of event data. The exploit is a classic example of an Insecure Direct Object Reference.
Affected Systems
The affected product is the Events Manager WordPress plugin, versions prior to 7.4.5. The vendor is listed as Unknown:Events Manager in the CNC registry. Only the stated version range applies; newer releases are assumed to have the fix.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the nature of the IDOR flaw suggests a high likelihood of exploitation by users who can already manage tickets. An attacker would craft a standard HTTP request to the plugin’s ticket‑update endpoint, supplying a ticket ID that belongs to another event. The lack of proper permission checks allows the reassignment to succeed. Without remediation, this flaw permits wide‑scale manipulation of event tickets across the site.
OpenCVE Enrichment