Junglewise Threat Intelligence

CVE-2026-81761: WpEvently broken access control for subscribers

CVE-2026-81761 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Technologies: MagePeople WpEvently. Vendors: MagePeople.

Executive brief

WpEvently is a WordPress plugin for managing events and bookings. A broken access control vulnerability allows subscribers (lower-privileged user accounts) to view or access content they should not have permission to see, such as other users' data or restricted pages. This could result in unauthorized exposure of sensitive event or customer information on WordPress sites using the plugin.

Technical details

The vulnerability is a broken access control flaw in WpEvently versions up to and including 5.5.0. An attacker with subscriber-level privileges can bypass authorization checks to access or perform actions restricted to higher-privilege roles, potentially viewing data belonging to other users. The vulnerability is network-accessible and requires only subscriber-level authentication. A patch is available in version 5.6.0 and later.

Affected products

  • Magepeople WpEvently <=5.5.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Version 5.6.0 released

References

Related threats