CVE-2026-84847: WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Affected Software
1 affected component
WordPress Quick Event Manager<=9.17
Event History
Sep 3, 2026
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior privileges to exploit the affected plugin.
2
Which installations are affected?
WordPress sites using Quick Event Manager version 9.17 or earlier are affected according to the available data. The provided information does not identify any configuration prerequisite.
3
What is the security impact?
The supplied CVSS vector indicates network-reachable exploitation with low attack complexity and no user interaction, with high impact to integrity. No confidentiality or availability impact is indicated.