PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39535 fullworks CVE debrief

A Missing Authorization vulnerability was found in the Display Eventbrite Events plugin for WordPress, affecting versions from n/a through 6.5.6. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a MEDIUM severity rating. The vulnerability enables attackers to exploit incorrectly configured access control security levels. Users of the plugin, particularly those with versions prior to 6.5.7, should be aware of this vulnerability and take necessary actions to secure their installations. It is recommended to update the plugin to version 6.5.7 or later and review access control configurations.

Vendor
fullworks
Product
Display Eventbrite Events
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the Display Eventbrite Events plugin for WordPress, particularly those with versions prior to 6.5.7, should be aware of this vulnerability and take necessary actions to secure their installations. This includes updating the plugin to version 6.5.7 or later and reviewing access control configurations.

Technical summary

The CVE-2026-39535 vulnerability is caused by a Missing Authorization issue in the Display Eventbrite Events plugin. This allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS score of 5.3 and is rated as MEDIUM severity. It affects versions of the plugin from n/a through 6.5.6. Users should verify their installations and update to version 6.5.7 or later.

Defensive priority

MEDIUM priority should be given to updating the Display Eventbrite Events plugin to a version that addresses this vulnerability.

Recommended defensive actions

  • Update the Display Eventbrite Events plugin to version 6.5.7 or later.
  • Review and adjust access control configurations for the plugin.
  • Monitor for any suspicious activity related to the plugin.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-08T09:16:26.213Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The Display Eventbrite Events plugin for WordPress has a Missing Authorization vulnerability, affecting versions from n/a through 6.5.6. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. Users should verify their installations and update to version 6.5.7 or later. The CVE score is 5.3 with a MEDIUM severity rating.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:26.213Z and has not been modified since then. The NVD entry is currently Deferred.