PatchSiren cyber security CVE debrief
CVE-2026-39535 fullworks CVE debrief
A Missing Authorization vulnerability was found in the Display Eventbrite Events plugin for WordPress, affecting versions from n/a through 6.5.6. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a MEDIUM severity rating. The vulnerability enables attackers to exploit incorrectly configured access control security levels. Users of the plugin, particularly those with versions prior to 6.5.7, should be aware of this vulnerability and take necessary actions to secure their installations. It is recommended to update the plugin to version 6.5.7 or later and review access control configurations.
- Vendor
- fullworks
- Product
- Display Eventbrite Events
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the Display Eventbrite Events plugin for WordPress, particularly those with versions prior to 6.5.7, should be aware of this vulnerability and take necessary actions to secure their installations. This includes updating the plugin to version 6.5.7 or later and reviewing access control configurations.
Technical summary
The CVE-2026-39535 vulnerability is caused by a Missing Authorization issue in the Display Eventbrite Events plugin. This allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS score of 5.3 and is rated as MEDIUM severity. It affects versions of the plugin from n/a through 6.5.6. Users should verify their installations and update to version 6.5.7 or later.
Defensive priority
MEDIUM priority should be given to updating the Display Eventbrite Events plugin to a version that addresses this vulnerability.
Recommended defensive actions
- Update the Display Eventbrite Events plugin to version 6.5.7 or later.
- Review and adjust access control configurations for the plugin.
- Monitor for any suspicious activity related to the plugin.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-04-08T09:16:26.213Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The Display Eventbrite Events plugin for WordPress has a Missing Authorization vulnerability, affecting versions from n/a through 6.5.6. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. Users should verify their installations and update to version 6.5.7 or later. The CVE score is 5.3 with a MEDIUM severity rating.
Official resources
-
CVE-2026-39535 CVE record
CVE.org
-
CVE-2026-39535 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:26.213Z and has not been modified since then. The NVD entry is currently Deferred.