PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40776 Arraytics CVE debrief

CVE-2026-40776 is a HIGH severity vulnerability in WP Event SOlution plugin versions <= 4.1.8. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].

Vendor
Arraytics
Product
WP Event SOlution
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of WP Event SOlution plugin versions <= 4.1.8 should apply patches or mitigations as available.

Technical summary

The vulnerability is caused by Unauthenticated Broken Access Control in WP Event SOlution plugin versions <= 4.1.8. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The weakness is categorized as CWE-862.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches or mitigations as available for WP Event SOlution plugin versions <= 4.1.8.
  • Review and update WP Event SOlution plugin to a version greater than 4.1.8.

Evidence notes

Evidence from Patchstack indicates a vulnerability in WP Event SOlution plugin.

Official resources

CVE-2026-40776 was published on 2026-06-15T21:16:50.347Z and last modified on 2026-06-15T21:24:32.790Z.