Wired Impact Volunteer Management
Wired Impact Volunteer Management manages volunteer records, opportunities, applications, and related activities in WordPress.
Wired Impact Volunteer Management (wired-impact-volunteer-management) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.5.
wired-impact-volunteer-managementCVE-2026-16546: Volunteer Management lets Subscribers delete other users' RSVPs
Wired Impact Volunteer Management before 2.8.2 omits authorization checks from an authenticated AJAX action and does not verify that the RSVP being removed belongs to the requesting user. A Subscriber can submit another RSVP identifier and remove arbitrary users from any volunteer opportunity. The public advisory does not disclose the AJAX action, identifier parameter, callback or deletion function.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-16546
Volunteer Management lets Subscribers delete other users' RSVPs
Wired Impact Volunteer Management before 2.8.2 omits authorization checks from an authenticated AJAX action and does not verify that the RSVP being removed belongs to the requesting user. A Subscriber can submit another RSVP identifier and remove arbitrary users from any volunteer opportunity. The public advisory does not disclose the AJAX action, identifier parameter, callback or deletion function.
|
2.8.2 |
CVE4.3
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24997
Wired Impact Volunteer Management: A security weakness
Wired Impact Volunteer Management is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 25, 2025 |
CVE-2025-26980
Wired Impact Volunteer Management: Cross-site scripting
Wired Impact Volunteer Management is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|