Impact
The vulnerability in WordPress The Events Calendar plugin versions 6.17.5 and earlier allows an attacker to bypass proper authorization controls. This flaw can enable a user to access or modify event data and administrative functions that should be restricted, potentially compromising the integrity and availability of the event management system. The impact is a direct escalation of privileges within the WordPress installation, with no evidence of code execution or data exfiltration specifically tied to this issue. However, unauthorized manipulation of events could disrupt scheduled content and affect site functionality.
Affected Systems
Affected systems include any WordPress site using the The Events Calendar plugin up to and including version 6.17.5. The CNA lists Nexcess as a vendor, but any installation of the plugin version 6.17.5 or earlier is vulnerable. The remedy is to upgrade the plugin to the latest version, at least 6.17.5.1.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely web‑based, involving HTTP requests to the plugin’s administrative endpoints, and would require the attacker to authenticate with a user account that has at least limited privileges. Because the flaw is a broken access control, an attacker could potentially elevate privilege within the scope of the plugin, but exploitation does not appear to require pre‑existing vulnerabilities or complex conditions.
OpenCVE Enrichment