PT-2025-34779 · WordPress · Event List

Tonn

·

Published

2025-08-26

·

Updated

2025-08-26

·

CVE-2025-6366

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Event List plugin for WordPress versions up to and including 2.0.4
Description: The Event List plugin for WordPress is susceptible to privilege escalation. This occurs because the plugin does not adequately validate a user’s capabilities before updating their profile within the el update profile() function. Authenticated attackers with Subscriber-level access or higher can potentially modify their capabilities to those of an administrator.
Recommendations: Event List plugin for WordPress version 2.0.4 and earlier: Update to a version later than 2.0.4.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-6366

Affected Products

Event List