Junglewise Threat Intelligence

CVE-2026-39518: EventPrime IDOR in WordPress plugin allows Subscriber data access

CVE-2026-39518 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: EventPrime. Vendors: EventPrime.

Executive brief

EventPrime is a WordPress plugin used for managing event calendars and bookings. A security flaw allows users with basic 'Subscriber' accounts to access or modify data they should not have permission to see by manipulating internal record identifiers. This could lead to the exposure of sensitive event information or unauthorized changes to database records.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the EventPrime plugin for WordPress (versions 4.3.0.0 and below). The flaw is categorized as CWE-639, where the application fails to properly validate if the requesting user has permission to access a specific object identifier. An attacker authenticated with Subscriber-level privileges can exploit this by modifying input parameters (such as IDs in web requests) to view or interact with data belonging to other users or the system. This can result in unauthorized data disclosure or limited data manipulation. The issue is resolved in version 4.3.0.1.

Affected products

  • EventPrime EventPrime <= 4.3.0.0

Timeline

  • 2026-02-17: other: Vulnerability reported by researcher James Pirstin
  • 2026-04-20: advisory: Patchstack published advisory and mitigation rules
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats