SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81802

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

WpEvently versions up to 5.6.0 are susceptible to unauthenticated Insecure Direct Object References (IDOR), allowing attackers to access sensitive data or perform unauthorized actions by manipulating object identifiers. This vulnerability poses a medium risk, particularly for organizations using this plugin in their WordPress installations. Users of WpEvently should prioritize patching or upgrading to mitigate potential data exposure and unauthorized access.

CVE
CVE-2026-81802
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.