CVE-2025-14029 | Community Events Plugin up to 1.5.6 on WordPress ajax_admin_event_approval eventlist authorization (EUVD-2026-3151)
A vulnerability was found in Community Events Plugin up to 1.5.6 on WordPress. It has been declared as problematic. This impacts the function ajax_admin_event_approval. The manipulation of the argument eventlist results in missing authorization.
This vulnerability is reported as CVE-2025-14029. The attack can be launched remotely. No exploit exists.