CVE-2026-105073: WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Event Solutionto a version that resolves this vulnerability.Fixed in 4.1.26
Event History
Frequently Asked Questions
Who can exploit this issue?
The vector is network-accessible and requires no privileges or user interaction. An unauthenticated remote attacker could exploit it.
What information could be exposed?
The available information identifies the issue as retrieval of embedded sensitive data and exposure of sensitive system information. It does not specify the exact data types or affected endpoints.
Which installations are affected?
WP Event Solution versions through 4.1.25 are affected. The provided information does not state whether any particular plugin configuration is required.