CyberRota Analysis
AI-GeneratedThe Events Manager plugin for WordPress is susceptible to an authorization bypass vulnerability, allowing unauthenticated attackers to access sensitive event information, including titles and locations, that should be restricted. This issue affects all versions up to 7.4.0 and poses a risk to the confidentiality of event data. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential exposure.
Original NVD Description
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.