Unauthenticated Insecure Direct Object References in WpEvently Plugin by WordPress
CVE-2026-81802

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-81802?

The WpEvently plugin for WordPress exhibits a vulnerability due to unauthenticated insecure direct object references. This issue allows attackers to access restricted data by manipulating URLs, which can lead to unauthorized information exposure. This vulnerability affects users of WpEvently versions up to 5.6.0, emphasizing the necessity of updating to secure future interactions. Protect your site by staying informed and applying necessary updates.

Affected Version(s)

WpEvently <= 5.6.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

benzdeus | Patchstack Bug Bounty Program
.