Executive brief
Events Made Easy is a WordPress plugin used to manage event registrations, bookings, and calendars. A security flaw in versions 3.1.3 and earlier allows unauthenticated users to perform actions they should not be authorized to access. This could lead to unauthorized modifications of event data or disruptions to the event management system, potentially impacting business operations and customer scheduling.
Technical details
A broken access control vulnerability exists in the Events Made Easy plugin for WordPress (versions up to and including 3.1.3) due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 6.5, indicating it can impact the integrity and availability of the plugin's data. The issue is resolved in version 3.1.4.
Affected products
- Franky (WordPress) Events Made Easy <= 3.1.3
Timeline
- 2026-04-29: other: Vulnerability reported by researcher HieuPenguinnn
- 2026-07-24: advisory: Patchstack published advisory details
- 2026-07-27: disclosed: CVE published to NVD dataset
- 2026-07-27: patched: Version 3.1.4 released to address the vulnerability