Medium severity5.3NVD Advisory· Published Jul 31, 2026· Updated Aug 26, 2026
CVE-2026-14843
CVE-2026-14843
Description
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.1.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.