Ovatheme Event List
cpe:2.3:a:event_list_project:event_list:*:*:*:*:wordpress:*:*
- <= 2.0.4
A privilege escalation vulnerability has been identified in the Event List plugin for WordPress, affecting all versions through 2.0.4. The issue arises because the plugin fails to properly validate user capabilities before allowing profile updates in the 'el_update_profile()' function. This flaw enables authenticated attackers with Subscriber-level access or higher to elevate their privileges to that of an administrator.
Exploitation of this vulnerability allows authenticated users to gain administrative privileges, potentially leading to unauthorized changes or actions within the WordPress site.
Users can update to version 2.0.5 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.