Broken Access Control in WpEvently Plugin by WordPress
CVE-2026-81761
4.3MEDIUM
What is CVE-2026-81761?
The WpEvently plugin for WordPress has a broken access control vulnerability that affects versions up to 5.5.0. This flaw allows unauthorized users to access sensitive subscriber functions, compromising overall site security. It is essential for users of the WpEvently plugin to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
WpEvently <= 5.5.0