← WordPress Vulnerabilities
WordPress security by component

Wired Impact Volunteer Management

Wired Impact Volunteer Management manages volunteer records, opportunities, applications, and related activities in WordPress.

Wired Impact Volunteer Management (wired-impact-volunteer-management) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.5.

Plugin slug: wired-impact-volunteer-management

CVE-2026-16546: Volunteer Management lets Subscribers delete other users' RSVPs

Wired Impact Volunteer Management before 2.8.2 omits authorization checks from an authenticated AJAX action and does not verify that the RSVP being removed belongs to the requesting user. A Subscriber can submit another RSVP identifier and remove arbitrary users from any volunteer opportunity. The public advisory does not disclose the AJAX action, identifier parameter, callback or deletion function.

PublishedAug 04, 2026
Known safe version2.8.2
Published vulnerabilities for wired-impact-volunteer-management
Safe version
Aug 04, 2026 CVE-2026-16546
Volunteer Management lets Subscribers delete other users' RSVPs
Wired Impact Volunteer Management before 2.8.2 omits authorization checks from an authenticated AJAX action and does not verify that the RSVP being removed belongs to the requesting user. A Subscriber can submit another RSVP identifier and remove arbitrary users from any volunteer opportunity. The public advisory does not disclose the AJAX action, identifier parameter, callback or deletion function.
2.8.2
CVE4.3
NVDPending
Feb 03, 2026 CVE-2026-24997
Wired Impact Volunteer Management: A security weakness
Wired Impact Volunteer Management is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending
Feb 25, 2025 CVE-2025-26980
Wired Impact Volunteer Management: Cross-site scripting
Wired Impact Volunteer Management is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending