Missing Authorization Vulnerability in Event Espresso Decaf by WordPress
CVE-2025-68007
6.5MEDIUM
What is CVE-2025-68007?
A missing authorization vulnerability has been discovered in Event Espresso 4 Decaf, where incorrectly configured access control security levels can be exploited. This flaw affects versions from n/a up to and including 5.0.37.decaf. Attackers might gain unauthorized access, leading to potential data breaches or manipulation of event settings, highlighting the importance of correctly configuring security controls to safeguard sensitive information.
Affected Version(s)
Event Espresso 4 Decaf 0 <= 5.0.37.decaf