Executive brief
WP Event SOlution, a WordPress plugin used for managing events and bookings, contains a security flaw that allows unauthorized individuals to access restricted data. An attacker could exploit this to view sensitive information without needing a login or any special permissions. This could lead to the exposure of customer or event data and potentially impact the organization's reputation.
Technical details
The WP Event SOlution plugin for WordPress suffers from a Broken Access Control vulnerability (CWE-862) due to missing authorization checks in its functional logic. This flaw allows an unauthenticated remote attacker to bypass intended access restrictions and perform actions or access data that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. According to the CVSS vector, the primary impact is on confidentiality (High), while integrity and availability are not directly affected. The issue is resolved in version 4.1.13.
Affected products
- Arraytics WP Event SOlution <= 4.1.12
Timeline
- 2025-10-29: other: Reported by researcher l3m3s
- 2026-06-15: advisory: Patchstack advisory published
- 2026-06-16: disclosed: NVD publication date