Executive brief
The Event post plugin for WordPress, which is used to manage and display event listings, contains a security flaw that allows unauthorized access to certain functions. An unauthenticated attacker could exploit this to view information or perform actions that should be restricted to site administrators. While the impact is considered moderate, it could lead to the exposure of internal site data.
Technical details
The Event post plugin for WordPress (versions <= 6.0.1) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This allows an unauthenticated remote attacker to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without any user interaction. At the time of the advisory, no official patch has been released, and the CVSS 3.1 base score is 5.3, primarily impacting confidentiality.
Affected products
- Bastien Ho (NOUS Ouvert Utile et Simple) Event post <= 6.0.1
Timeline
- 2026-01-28: other: Vulnerability reported by researcher Que Thanh Tuan
- 2026-07-22: advisory: Initial advisory published by Patchstack
- 2026-07-23: disclosed: CVE published to NVD