What the vulnerability does
01Description
Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1.
Explanation of Vulnerability in Simple Terms
02Summary
Registrations for the Events Calendar plugin for WordPress does not properly check user permissions before allowing modifications to event registration data. A logged-in user with low privileges can alter or disrupt registrations for events, affecting data integrity across the site. The vulnerability requires a valid WordPress account but no special role or capability.
What an attacker can do
03Attacker Capabilities
Modify or disrupt event registrations without proper authorization.
Potential impact on your site
04Site Impact
Event registration data can be altered by unauthorized users, compromising event management and attendee records.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with low-level privileges.
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated