CVE-2026-84847
moderateUnauthenticated Broken Access Control in Quick Event Manager WordPress Plugin
Quick Event Manager, a WordPress event calendar plugin, in versions up to and including 9.17, performs a privileged action without a required authorization check (CWE-862, Missing Authorization), allowing an unauthenticated attacker to bypass access controls over the network (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U). By sending crafted unauthenticated requests to the affected plugin function, an attacker can invoke functionality that should require a logged-in, authorized user. Per the CVSS scoring (C:N/I:H/A:N), the impact is limited to integrity: the attacker can modify plugin-managed data or settings, likely event content or plugin configuration, without reading sensitive data or disrupting site availability. Any WordPress site running Quick Event Manager 9.17 or earlier is affected. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known; the flaw was disclosed via Patchstack (CNA) and EPSS currently estimates only a 0.2% chance of exploitation within 30 days.
What to do: Sites running Quick Event Manager 9.17 or earlier should update to the first patched release after 9.17 as soon as it becomes available and confirm the fix in the plugin changelog. Until patched, consider deactivating the plugin if event functionality is not essential, and review web server logs for unauthenticated requests targeting the plugin's endpoints or AJAX/REST actions. Given the unauthenticated nature of the flaw but the absence of a public PoC and the low EPSS score, immediate risk is low, but patching should not be deferred.
| Quick Event Manager (WordPress plugin) | <= 9.17 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.