CVE-2026-97300: WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
Affected Software
1 affected component
WordPress WP Event SOlution<=4.1.25
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceto a version that resolves this vulnerability.Fixed in 4.1.26
Event History
Oct 6, 2026
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges to exploit it.
2
What versions are affected?
WP Event Solution versions up to and including 4.1.25 are affected.
3
What is the potential impact?
The supplied severity vector indicates low integrity and availability impact, with no confidentiality impact. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.