CVE-2025-14029: Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter
The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxadmineventapproval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events via the 'eventlist' parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14029?
CVE-2025-14029 has a medium severity rating due to its potential for unauthorized data modification.
How do I fix CVE-2025-14029?
To fix CVE-2025-14029, update the Community Events plugin to version 1.5.7 or later.
What systems are affected by CVE-2025-14029?
CVE-2025-14029 affects all versions of the Community Events plugin for WordPress up to and including version 1.5.6.
What type of attack can be executed using CVE-2025-14029?
CVE-2025-14029 allows unauthorized users to approve events, leading to potential manipulation of event listings.
Is authentication required to exploit CVE-2025-14029?
No, CVE-2025-14029 can be exploited by unauthenticated users due to a missing capability check.