The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing nonce validation on the event deletion functionality. This makes it possible for unauthenticated attackers to delete arbitrary events via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcez
Sourcez seatt: Simple Event Attendance Wordpress Wordpress wordpress |
|
| Vendors & Products |
Sourcez
Sourcez seatt: Simple Event Attendance Wordpress Wordpress wordpress |
Sat, 14 Feb 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing nonce validation on the event deletion functionality. This makes it possible for unauthenticated attackers to delete arbitrary events via a forged request granted they can trick an administrator into performing an action such as clicking on a link. | |
| Title | SEATT: Simple Event Attendance <= 1.5.0 - Cross-Site Request Forgery to Arbitrary Event Deletion | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-02-14T04:35:42.467Z
Updated: 2026-02-18T18:49:12.098Z
Reserved: 2026-02-05T14:45:19.212Z
Link: CVE-2026-1983
Updated: 2026-02-18T18:49:09.333Z
Status : Awaiting Analysis
Published: 2026-02-14T05:16:20.140
Modified: 2026-02-18T17:52:44.520
Link: CVE-2026-1983
No data.