Executive brief
WpEvently, a WordPress plugin used for event management, contains a security flaw that could allow unauthorized individuals to manipulate site data. An attacker could exploit this to change event details or other plugin-related information without needing a login. This could lead to misinformation on your website or disruption of event booking operations.
Technical details
The WpEvently plugin for WordPress (versions 5.3.3 and earlier) is vulnerable to a flaw classified as Improper Validation of Specified Quantity in Input (CWE-1284). This vulnerability allows an unauthenticated remote attacker to submit crafted requests that bypass intended logic, leading to unauthorized data modification (Integrity: High). The attack vector is network-based with low complexity and requires no user interaction. The issue is addressed in version 5.3.4.
Affected products
- Magepeople inc. WpEvently <= 5.3.3
Timeline
- 2026-05-08: other: Reported by researcher dodoh4t
- 2026-05-26: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published to NVD
- 2026-05-26: patched: Version 5.3.4 released