Home

Description

Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Event Manager, Event Calendar and Booking Plugin: from n/a through 4.0.24.

PUBLISHED Reserved 2025-06-19 | Published 2025-08-14 | Updated 2025-08-14 | Assigner Patchstack




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version
affected

Credits

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance) finder

References

patchstack.com/...y-content-deletion-vulnerability?_s_id=cve vdb-entry

cve.org (CVE-2025-52731)

nvd.nist.gov (CVE-2025-52731)

Download JSON