Volunteer Management lets Subscribers delete other users' RSVPs
Wired Impact Volunteer Management before 2.8.2 omits authorization checks from an authenticated AJAX action and does not verify that the RSVP being removed belongs to the requesting user. A Subscriber can submit another RSVP identifier and remove arbitrary users from any volunteer opportunity. The public advisory does not disclose the AJAX action, identifier parameter, callback or deletion function.
- Component
- Wired Impact Volunteer Management
- Plugin slug
wired-impact-volunteer-management- Affected
- < 2.8.2
- Safe version
2.8.2- Published
- Aug 04, 2026
- Weakness
- CWE-862 — Missing Authorization
This CVE was published Aug 04, 2026 and is one of 3 known issues for this plugin.
Update, patch or deactivate.
Update Wired Impact Volunteer Management to 2.8.2 or later. Review RSVP removals by low-privilege accounts and restore unauthorized deletions from a trusted backup or source record.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N