CVE-2026-25312
7.5Metagauss · EventPrime
A missing authorization vulnerability in the Metagauss EventPrime WordPress plugin allows unauthenticated attackers to bypass access control checks.
Executive summary
A critical missing authorization flaw in the Metagauss EventPrime plugin enables unauthenticated attackers to manipulate access control security levels, posing a significant risk to event management integrity.
Vulnerability
This vulnerability is a CWE-862 Missing Authorization flaw, which allows unauthenticated remote attackers to perform actions due to insufficient capability checks within the plugin. The issue resides in the event calendar management functionality, enabling unauthorized modifications to security settings.
Business impact
The ability for an unauthenticated user to bypass access control leads to unauthorized modification of system data, specifically regarding payment or event management configurations. With a CVSS score of 7.5, this high-severity vulnerability could result in significant operational disruption, financial loss, or the compromise of event data integrity.
Remediation
Immediate Action: Update the EventPrime plugin to the latest version available from the vendor, which addresses the authorization oversight.
Proactive Monitoring: Review application access logs for unusual requests or unauthorized attempts to access administrative endpoints associated with the EventPrime plugin.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules designed to detect and block unauthorized requests directed at plugin-specific administrative or configuration endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention, as it allows unauthenticated actors to manipulate sensitive plugin controls. Administrators must prioritize updating the EventPrime plugin to a patched version to restore proper access control mechanisms and prevent potential exploitation of the identified security gap.
More Metagauss CVEs
Sources
Originally found and disclosed by Dr. M Fahad Khan | Patchstack Bug Bounty Program, per the CVE Program record.