Junglewise Threat Intelligence

CVE-2026-27398: WP Chill RSVP and Event Management missing authorization

CVE-2026-27398 · Severity: medium · CVSS 5.3 · Published 2026-05-25

Vendors: WP Chill.

Executive brief

The RSVP and Event Management plugin for WordPress, used to manage event registrations and attendee lists, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions or access features that should be restricted to administrators. While the impact is considered low, it could allow attackers to interfere with event management data without needing a password.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the WP Chill RSVP and Event Management plugin for WordPress through version 2.7.16. The flaw stems from a failure to implement proper authorization or nonce checks on certain functions, allowing unauthenticated remote attackers to execute actions that should require higher privileges. The attack vector is network-based with low complexity and requires no user interaction. An attacker can exploit this to modify data or settings, though the CVSS assessment indicates no impact on confidentiality or availability. The issue is resolved in version 2.7.17.

Affected products

  • WP Chill RSVP and Event Management <= 2.7.16

Timeline

  • 2025-11-11: other: Reported by researcher daroo
  • 2026-05-25: advisory: Published by Patchstack and NVD
  • 2026-05-25: patched: Fixed in version 2.7.17

References

Related threats