Executive brief
WpEvently is a WordPress plugin for managing events and bookings. A broken access control vulnerability allows subscribers (lower-privileged user accounts) to view or access content they should not have permission to see, such as other users' data or restricted pages. This could result in unauthorized exposure of sensitive event or customer information on WordPress sites using the plugin.
Technical details
The vulnerability is a broken access control flaw in WpEvently versions up to and including 5.5.0. An attacker with subscriber-level privileges can bypass authorization checks to access or perform actions restricted to higher-privilege roles, potentially viewing data belonging to other users. The vulnerability is network-accessible and requires only subscriber-level authentication. A patch is available in version 5.6.0 and later.
Affected products
- Magepeople WpEvently <=5.5.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Version 5.6.0 released