Access violation vulnerability in Event List 2.0.4

The Event List plugin for WordPress has a security issue that allows attackers with certain levels of access to gain more privileges than they should have. This problem affects all versions of the plugin up to and including 2.0.4. The issue is caused by the plugin not properly checking a user’s permissions before allowing them to update their profile. This means that attackers who have at least Subscriber-level access can change their permissions to that of an administrator.

Detected in:

Event List open vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.