Loading market data...
← Back to CVE feed

CVE-2026-14843

MEDIUM CVSS 5.3 View on NVD ↗

Description

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Jul 31, 2026 07:16 UTC Modified: Jul 31, 2026 14:16 UTC