Description
The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events via the 'eventlist' parameter.
Problem types
Product status
* (semver)
Timeline
| 2025-12-04: | Vendor Notified |
| 2026-01-16: | Disclosed |
Credits
Itthidej Aramsri
References
www.wordfence.com/...-b6bc-462a-98ef-30e6a68d74cf?source=cve
plugins.trac.wordpress.org/...nts/trunk/community-events.php
plugins.trac.wordpress.org/...ags/1.5.5/community-events.php
plugins.trac.wordpress.org/...ags/1.5.5/community-events.php
plugins.trac.wordpress.org/...y-events&sfp_email=&sfph_mail=