Junglewise Threat Intelligence

CVE-2026-81802: WpEvently Insecure Direct Object References (IDOR)

CVE-2026-81802 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: MagePeople WpEvently. Vendors: MagePeople.

Executive brief

WpEvently is a WordPress plugin for event management and ticketing. The plugin contains an unauthenticated IDOR vulnerability that allows attackers to access and potentially modify other users' event data by manipulating object IDs in requests. This could expose sensitive booking information, customer details, and allow unauthorized access to private event data.

Technical details

The vulnerability is an Insecure Direct Object References (IDOR) flaw in WpEvently versions up to 5.6.0 that does not properly validate authorization before exposing objects tied to user-controlled IDs. The vulnerability is unauthenticated, meaning an attacker does not need valid credentials to exploit it. By modifying ID parameters in API calls or URLs, an attacker can enumerate and access other users' event records, bookings, and potentially sensitive customer information. The vulnerability has been patched in version 5.6.4 and later.

Affected products

  • MagePeople WpEvently 5.6.0 and earlier

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Patched in version 5.6.4
  • 2026-08-30: other: Reported by benzdeus

References

Related threats