Junglewise Threat Intelligence

CVE-2026-39535: fullworks Display Eventbrite Events missing authorization

CVE-2026-39535 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Display Eventbrite Events plugin for WordPress, which allows site owners to integrate Eventbrite event listings, contains a security flaw in its access control mechanisms. This vulnerability could allow an unauthorized person to perform actions or access information that should be restricted to administrators. While the impact is considered moderate, it could lead to unauthorized changes to how events are displayed or the exposure of internal configuration details.

Technical details

A missing authorization vulnerability (CWE-862) exists in the fullworks Display Eventbrite Events plugin (widget-for-eventbrite-api) for WordPress. The flaw stems from incorrectly configured access control security levels within the plugin's API handling components. An unauthenticated remote attacker can exploit this lack of validation to execute functions or access data that should require higher privilege levels. The vulnerability is resolved in version 6.5.7, which introduces proper authorization checks.

Affected products

  • fullworks Display Eventbrite Events (widget-for-eventbrite-api) <= 6.5.6

Timeline

  • 2026-01-19: other: Vulnerability reported by researcher
  • 2026-02-18: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published
  • 2026-06-17: patched: Patch confirmed available in version 6.5.7

References