WordPress Event Manager, Event Calendar and Booking Plugin Missing Authorization Vulnerability Allowing Arbitrary Content Deletion
Vulnerability
A missing authorization vulnerability has been identified in the WordPress Event Manager, Event Calendar and Booking Plugin, affecting versions through 4.0.24. This vulnerability allows exploitation of improperly configured access control, potentially leading to arbitrary content deletion on affected websites.
Impact
Exploitation of this vulnerability could result in the unauthorized deletion of content, such as posts, pages, or media, from the affected WordPress site.
Remediation
Users of the WordPress Event Manager, Event Calendar and Booking Plugin should update to version 4.0.25 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
