CVE-2025-63006: WordPress EventPrime plugin <= 4.2.4.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.4.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63006?
CVE-2025-63006 has a critical severity level due to its potential for unrestricted access to sensitive event management functionality.
How do I fix CVE-2025-63006?
To fix CVE-2025-63006, update Metagauss EventPrime to the latest version above 4.2.4.1, ensuring proper access control configurations.
What is the impact of CVE-2025-63006 if left unaddressed?
If left unaddressed, CVE-2025-63006 could allow unauthorized users to access and manipulate calendar events, leading to data leakage or tampering.
Which versions of Metagauss EventPrime are affected by CVE-2025-63006?
CVE-2025-63006 affects Metagauss EventPrime versions from n/a up to and including 4.2.4.1.
Is CVE-2025-63006 a remote exploit?
Yes, CVE-2025-63006 can potentially be exploited remotely due to missing authorization checks in the application.