Junglewise Threat Intelligence

CVE-2026-84847: Quick Event Manager broken access control

CVE-2026-84847 · Severity: high · CVSS 7.5 · Published 2026-09-03

Executive brief

Quick Event Manager is a WordPress plugin used to create and manage events on websites. An unauthenticated broken access control vulnerability allows attackers to bypass security controls and access event data or perform actions they should not be permitted to access, potentially exposing sensitive event information or enabling unauthorized modifications without needing to log in.

Technical details

This vulnerability is a broken access control flaw in Quick Event Manager versions 9.17 and earlier that allows unauthenticated attackers to access restricted functionality or data. The vulnerability has no authentication requirements and is remotely exploitable over the network. Attackers can view or manipulate event data they should not have access to. No official patch is currently available; affected sites should update to a patched version or disable the plugin until a fix is released.

Affected products

  • Bright Plugins Quick Event Manager <= 9.18

Timeline

  • 2026-09-03: disclosed
  • 2026-04-25: other: Initially reported to vendor

References

Related threats