CVE-2026-81759: WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability
Published Aug 28, 2026
·Updated
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Affected Software
1 affected component
WordPress WpEvently<=5.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WpEvently pluginto a version that resolves this vulnerability.Fixed in 5.6.0
Event History
Aug 28, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level permissions in WordPress. The attack can be performed remotely and does not require user interaction.
2
What is the potential impact?
The vulnerability can affect integrity and availability, while confidentiality is not impacted according to the supplied CVSS vector.
3
Which WpEvently versions are affected?
WpEvently versions 5.5.0 and earlier are affected.