Impact
Unauthenticated Broken Access Control in WP Event Solution versions up to and including 4.1.25 allows attackers without valid user credentials to access privileged functions or data within the plugin. This vulnerability can be leveraged to alter events, view sensitive information, or perform other actions normally restricted to authenticated administrators, potentially impacting data confidentiality, integrity, and availability of the hosted website.
Affected Systems
The Arraytics "WP Event Solution" WordPress plugin, specifically versions 4.1.25 and earlier, is affected. Sites that have installed these versions are at risk unless they upgrade to a newer release that contains the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is via unauthenticated web requests to the plugin’s administrative endpoints, which do not require user authentication. Exploitation is possible for any visitor to the site, making it a universal concern for sites running the vulnerable plugin.
OpenCVE Enrichment