What the vulnerability does
01Description
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
Explanation of Vulnerability in Simple Terms
WP Event Solution versions up to 4.1.19 lack proper authorization checks, allowing authenticated users with low privileges to modify site data and cause service disruptions. An attacker with a basic user account can alter event information and trigger availability issues without needing admin rights. Update to a version newer than 4.1.19 to resolve this vulnerability.
What an attacker can do
Modify event data and disrupt site availability with a low-privilege user account.
Potential impact on your site
Unauthorized users can alter events and cause the site to become unavailable or unstable.
Conditions required to exploit
Attacker must have a valid user account with low privileges on the site.
Key dates
External resources
Related vulnerabilities