WordPress Plugin Vulnerabilities

Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR

Description

The plugin does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.

Proof of Concept

Affects Plugins

Fixed in 3.1.4

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Haitam Lazaar
Submitter
Haitam Lazaar
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-13 (about 17 days ago)

Other