CVE-2026-82223: WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
Affected Software
1 affected component
wordpress/wp-event-solution<=4.1.22
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Event SOlution Pluginto a version that resolves this vulnerability.Fixed in 4.1.23
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are exposed?
WordPress sites using the WP Event SOlution plugin at version 4.1.22 or earlier are affected.
2
What does an attacker need to exploit this issue?
The issue is remotely exploitable with low attack complexity. It requires no authentication, no user interaction, and no privileges.
3
What is the expected impact of a successful exploit?
The available severity vector indicates low impact to integrity and availability. No confidentiality impact is indicated.