CVE-2025-54705: WordPress WpEvently plugin <= 4.4.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.4.6.
Other sources
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.4.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54705?
CVE-2025-54705 has been classified as a missing authorization vulnerability that may lead to unauthorized access.
How do I fix CVE-2025-54705?
To fix CVE-2025-54705, you should upgrade WpEvently to the latest version beyond 4.4.6 to ensure proper access controls.
What versions of WpEvently are affected by CVE-2025-54705?
CVE-2025-54705 affects WpEvently versions from n/a up to and including 4.4.6.
What causes the vulnerability CVE-2025-54705?
CVE-2025-54705 is caused by incorrectly configured access control security levels in the WpEvently plugin.
Who is affected by CVE-2025-54705?
Any users of the WpEvently plugin up to version 4.4.6 are potentially affected by CVE-2025-54705.