Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
CVE-2026-14843
Description
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.1.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/0b445129-19e2-4240-a79a-d3190161d369/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.