PT-2026-81244 · WordPress · Events 2

·

CVE-2026-77144

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Events 2 (affected versions not specified)
Description The frontend management plugin contains a broken access control issue. The system attributes a newly created event to the submitting user's organizer record only if the request does not specify an organizer. Because the permission check only verifies that the submitting user possesses any organizer role, a user with frontend event management access can create an event and attribute it to a different organizer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77144

Affected Products

Events 2