Impact
The Events Manager WordPress plugin versions 7.4.1 through 7.4.4 do not enforce the correct scope for logged‑in event and location searches when a caller supplies an explicit 'owner' parameter. This deficiency allows an authenticated user with low privileges to view unpublished, pending, or trashed events and venue details from other accounts, including complete street addresses. The vulnerability exposes sensitive business and personal data that would normally be restricted, thereby compromising confidentiality.
Affected Systems
WordPress sites running the Events Manager plugin, specifically versions 7.4.1, 7.4.2, 7.4.3, and 7.4.4. Versions 7.4.5 or later contain a fix and are not affected.
Risk and Exploitability
The description indicates that an attacker must be authenticated on the WordPress site in order to supply the 'owner' parameter; this inference is based on the phrase 'allows a low‑privileged user' in the vulnerability description. Once authenticated, the attacker can request event or location data that belongs to other users by adding the 'owner' parameter to a legitimate search request. The CVSS score is 4.3 and no EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The potential to expose private venue addresses and unpublished events indicates a noteworthy confidentiality risk. No publicly disclosed exploit is currently known; however, the possibility of informational leakage warrants timely remediation.
OpenCVE Enrichment