ZeroHour

CVE-2026-84847

moderate

Unauthenticated Broken Access Control in Quick Event Manager WordPress Plugin

CVSS 3.1
7.5 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Quick Event Manager, a WordPress event calendar plugin, in versions up to and including 9.17, performs a privileged action without a required authorization check (CWE-862, Missing Authorization), allowing an unauthenticated attacker to bypass access controls over the network (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U). By sending crafted unauthenticated requests to the affected plugin function, an attacker can invoke functionality that should require a logged-in, authorized user. Per the CVSS scoring (C:N/I:H/A:N), the impact is limited to integrity: the attacker can modify plugin-managed data or settings, likely event content or plugin configuration, without reading sensitive data or disrupting site availability. Any WordPress site running Quick Event Manager 9.17 or earlier is affected. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known; the flaw was disclosed via Patchstack (CNA) and EPSS currently estimates only a 0.2% chance of exploitation within 30 days.

What to do: Sites running Quick Event Manager 9.17 or earlier should update to the first patched release after 9.17 as soon as it becomes available and confirm the fix in the plugin changelog. Until patched, consider deactivating the plugin if event functionality is not essential, and review web server logs for unauthenticated requests targeting the plugin's endpoints or AJAX/REST actions. Given the unauthenticated nature of the flaw but the absence of a public PoC and the low EPSS score, immediate risk is low, but patching should not be deferred.

Affected
Quick Event Manager (WordPress plugin)<= 9.17
Estimated exposure
moderateon the order of ~10,000 WordPress sites (order-of-magnitude estimate) — No active-install count was included in the provided data; the estimate reflects this long-standing WordPress.org event-calendar plugin's typical install base, historically in the neighborhood of ten thousand active installs.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.