Description
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Broken Access Control
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated Broken Access Control in WP Event Solution versions up to and including 4.1.25 allows attackers without valid user credentials to access privileged functions or data within the plugin. This vulnerability can be leveraged to alter events, view sensitive information, or perform other actions normally restricted to authenticated administrators, potentially impacting data confidentiality, integrity, and availability of the hosted website.

Affected Systems

The Arraytics "WP Event Solution" WordPress plugin, specifically versions 4.1.25 and earlier, is affected. Sites that have installed these versions are at risk unless they upgrade to a newer release that contains the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is via unauthenticated web requests to the plugin’s administrative endpoints, which do not require user authentication. Exploitation is possible for any visitor to the site, making it a universal concern for sites running the vulnerable plugin.

Generated by OpenCVE AI on October 6, 2026 at 06:21 UTC.

Remediation

Vendor Solution

Update the WordPress Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin to the latest available version (at least 4.1.26).


OpenCVE Recommended Actions

  • Update the WP Event Solution plugin to version 4.1.26 or later to apply the vendor‑provided fix.
  • If an immediate update is not possible, block unauthenticated access to the plugin’s admin URLs by using firewall rules, .htaccess restrictions, or a web application firewall to enforce authentication.
  • Continuously monitor web server logs for suspicious requests targeting the plugin’s endpoints to detect and respond to attempted exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
Title WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability
Weaknesses CWE-799
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T05:14:51.890Z

Reserved: 2026-09-24T10:23:27.497Z

Link: CVE-2026-97300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:02.110

Modified: 2026-10-06T06:17:02.110

Link: CVE-2026-97300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T06:30:08Z

Weaknesses
  • CWE-799

    Improper Control of Interaction Frequency