Junglewise Threat Intelligence

CVE-2026-42669: EventPrime Missing Authorization in Access Control Security Levels

CVE-2026-42669 · Severity: high · CVSS 7.5 · Published 2026-06-02

Technologies: EventPrime. Vendors: EventPrime.

Executive brief

EventPrime, a WordPress plugin used for event management and calendar scheduling, contains a security flaw that allows unauthorized users to bypass access controls. This could allow an attacker to perform administrative actions or modify event data without proper permission. Such vulnerabilities can disrupt business operations and compromise the integrity of event listings on the website.

Technical details

A missing authorization vulnerability (CWE-862) exists in the EventPrime plugin for WordPress up to version 4.3.2.0. The flaw stems from insufficient validation of user permissions when accessing certain functions or security levels, allowing an unauthenticated attacker to execute actions that should be restricted to higher-privileged users. The attack vector is remote via the network with no user interaction required. Successful exploitation allows an attacker to modify data (Integrity: High) but does not directly lead to data disclosure or service downtime according to the CVSS vector. The issue is resolved in version 4.3.2.1.

Affected products

  • EventPrime EventPrime <= 4.3.2.0

Timeline

  • 2026-04-12: other: Reported by Evan NR
  • 2026-05-12: advisory: Patchstack advisory published
  • 2026-06-02: disclosed: NVD publication date
  • 2026-05-12: patched: Version 4.3.2.1 released

References

Related threats