CVE-2026-25312: WordPress EventPrime plugin <= 4.2.8.3 - Payment Bypass vulnerability
Published Mar 19, 2026
·Updated
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3.
Affected Software
1 affected component
Metagauss EventPrime (eventprime-event-calendar-management) WordPress plugin<=4.2.8.3
Remediation
Information
Update the WordPress EventPrime Plugin to the latest available version (at least 4.2.8.4).
Event History
Mar 19, 2026
CVE Published
via MITRE·07:20 AM
Data Sourced
via MITRE·07:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25312?
CVE-2026-25312 is considered a medium severity vulnerability due to its potential impact on payment processing and access control.
2
How do I fix CVE-2026-25312?
To fix CVE-2026-25312, update the EventPrime plugin to the latest version beyond 4.2.8.3.
3
What causes CVE-2026-25312?
CVE-2026-25312 is caused by incorrect access control configurations in the EventPrime plugin.
4
Who is affected by CVE-2026-25312?
CVE-2026-25312 affects users of the EventPrime plugin version 4.2.8.3 and earlier.
5
Can CVE-2026-25312 lead to unauthorized transactions?
Yes, CVE-2026-25312 can lead to unauthorized transactions due to payment bypass vulnerabilities.