PT-2026-81244 · WordPress · Events 2
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Events 2 (affected versions not specified)
Description
The frontend management plugin contains a broken access control issue. The system attributes a newly created event to the submitting user's organizer record only if the request does not specify an organizer. Because the permission check only verifies that the submitting user possesses any organizer role, a user with frontend event management access can create an event and attribute it to a different organizer.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events 2