Missing Authorization Vulnerability in WordPress Event Manager and Booking Plugin
CVE-2025-52731

7.5HIGH

What is CVE-2025-52731?

A serious security issue has been identified in the WordPress Event Manager and Booking Plugin, where missing authorization can lead to improperly configured access control levels. This vulnerability allows unauthorized users to potentially exploit the system, resulting in unauthorized actions or access to sensitive data. It is crucial for users of the affected versions (up to 4.0.24) to take immediate action to secure their installations.

Affected Version(s)

WordPress Event Manager, Event Calendar and Booking Plugin <= 4.0.24

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.