Executive brief
EventPrime is a WordPress plugin used for managing event calendars and bookings. A security vulnerability in this plugin allows logged-in users with basic 'Subscriber' permissions to inject malicious data that the server processes incorrectly. This could lead to a complete takeover of the website, unauthorized access to sensitive data, or a total service outage.
Technical details
The EventPrime plugin for WordPress (versions <= 4.3.4.1) is vulnerable to PHP Object Injection due to improper deserialization of user-supplied input. An attacker with Subscriber-level privileges can exploit this by submitting specially crafted input to a vulnerable endpoint. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, SQL injection, or arbitrary file deletion. The issue is fixed in version 4.3.4.2.
Affected products
- EventPrime EventPrime <= 4.3.4.1
Timeline
- 2026-05-31: other: Reported by VanTastic
- 2026-06-25: disclosed
- 2026-06-25: patched: Fixed in version 4.3.4.2