Missing Authorization Vulnerability in Metagauss EventPrime Calendar Management
CVE-2025-69358
7.5HIGH
What is CVE-2025-69358?
The Metagauss EventPrime Event Calendar Management plugin is susceptible to a missing authorization issue that allows users to exploit incorrectly configured access control security levels. This vulnerability affects EventPrime versions from n/a up to and including 4.2.6.0. Attackers might gain unauthorized access to restricted functionalities, posing a significant threat to data integrity and user privacy.
Affected Version(s)
EventPrime 0 <= 4.2.6.0