CVE-2026-103684: WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arraytics WP Event Solutionto a version that resolves this vulnerability.Fixed in 4.1.26
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is rated network-accessible with low attack complexity and requires no privileges or user interaction. This indicates that an unauthenticated remote attacker may be able to exploit the affected access-control weakness.
Which plugin versions are affected?
WP Event Solution versions through 4.1.25 are affected. The provided data does not identify a fixed version.
What is the potential impact?
The reported severity is medium, with a CVSS score of 5.3. The vector indicates no confidentiality or availability impact, but a low integrity impact.