Executive brief
WpEvently is a WordPress plugin for managing events, tickets, and bookings. A broken access control vulnerability allows users with contributor privileges to access or perform actions they should not be authorized to perform, potentially exposing event data or modifying event settings inappropriately.
Technical details
This is a broken access control vulnerability (OWASP A1) in WpEvently versions up to 5.5.0 where insufficient authorization checks allow authenticated users with contributor role to access sensitive functionality or data. The vulnerability is triggered by an authenticated attacker with contributor-level privileges on the WordPress site. The attack requires no network access beyond normal WordPress authentication and no user interaction from administrators. An attacker can bypass access controls to view or modify resources they should not have permission to access. The vulnerability has been patched in version 5.6.0.
Affected products
- Magepeople WpEvently <=5.5.0
Timeline
- 2026-08-27: disclosed: Vulnerability published by Patchstack
- 2026-08-27: patched: Fix available in version 5.6.0