CVE-2026-81802
Received Received - Intake

Unauthenticated IDOR in WpEvently Plugin

Vulnerability report for CVE-2026-81802, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Patchstack

Description

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack wpevently to 5.6.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Unauthenticated Insecure Direct Object References (IDOR) vulnerability in the WpEvently WordPress plugin versions 5.6.0 and below. It allows unauthenticated attackers to bypass authorization and access sensitive files, folders, or interact with the database by exploiting direct object references.

Detection Guidance

To detect this IDOR vulnerability in WpEvently <= 5.6.0, inspect network traffic for unauthorized direct object references in API calls or file access attempts. Check web server logs for suspicious requests targeting sensitive endpoints without authentication. Use tools like Burp Suite or OWASP ZAP to scan for IDOR patterns in plugin interactions.

Impact Analysis

This vulnerability may allow attackers to access sensitive data or modify database entries without authentication. It is considered moderately dangerous and could be targeted in mass-exploit campaigns affecting thousands of websites. Immediate action is advised to prevent potential breaches.

Mitigation Strategies

Immediately update WpEvently to version 5.6.4 or later. If updating is not possible, apply Patchstack's mitigation rule to block attacks temporarily. Disable the plugin if unused, restrict file permissions, and monitor for unauthorized access attempts. Consider enabling auto-updates for vulnerable plugins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81802. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart