Missing Authorization Issue in WpEvently by MagePeopleTeam
CVE-2025-66083
4.3MEDIUM
What is CVE-2025-66083?
The WpEvently plugin by MagePeopleTeam contains a Missing Authorization vulnerability that stems from incorrectly configured access control security levels. This flaw allows attackers to exploit the plugin and gain unauthorized access to restricted areas or functionalities, potentially leading to unauthorized actions on affected WordPress sites. Users of WpEvently versions up to 5.0.4 should take immediate steps to review their access control settings and apply any available patches to mitigate this risk.
Affected Version(s)
WpEvently <= n/a