Wordpress Alert: Event-registration data exposure
An event plugin lists attendee details to the wrong users. Names and contact information may be disclosed.
What it looks like
An event plugin lists attendee details to the wrong users.
Why it matters
Names and contact information may be disclosed.
What to check
Review attendee endpoints and exports for capability checks.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress REST endpoint permissions.
- Categories: WordPress
- Tags: #WordPress Security, #Plugin Security