What is CVE-2026-14843?
This vulnerability exists in the Events Made Easy WordPress plugin before version 3.1.4. The plugin fails to verify if the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying solely on a public nonce without per-record token or ownership checks. This allows unauthenticated attackers to modify data, and immediate update to version 3.1.4 is required.
Azərbaycanca: Bu zəiflik Events Made Easy WordPress plaginin 3.1.4-dən əvvəlki versiyalarında aşkarlanıb. Plagin, autentifikasiya olunmamış məlumat dəyişikliyi sorğularını idarə edərkən istifadəçinin hədəf qeydi dəyişdirmək icazəsini yoxlamır, yalnız ictimai nonce-ə güvənir. Nəticədə autentifikasiya olunmamış hücumçular məlumatları icazəsiz dəyişdirə bilər, plagin dərhal 3.1.4 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What is the cause of CVE-2026-14843 in the Events Made Easy WordPress plugin?
The vulnerability is due to the plugin failing to verify if the requester is authorized to modify the targeted record when handling unauthenticated data-change requests, relying solely on a public nonce without per-record token or ownership checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.