CVE-2026-81802: WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerability
Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WpEvently pluginto a version that resolves this vulnerability.Fixed in 5.6.4
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
Which installations are affected?
WpEvently plugin versions 5.6.0 and earlier are affected. The available information does not state whether a particular plugin configuration or feature must be enabled.
What impact is reported from successful exploitation?
The reported severity vector indicates low integrity and availability impact, with no reported confidentiality impact. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.