WordPress security changelog
MEDIUM CVE-2026-16546 Received

Volunteer Management lets Subscribers delete other users' RSVPs

Wired Impact Volunteer Management before 2.8.2 omits authorization checks from an authenticated AJAX action and does not verify that the RSVP being removed belongs to the requesting user. A Subscriber can submit another RSVP identifier and remove arbitrary users from any volunteer opportunity. The public advisory does not disclose the AJAX action, identifier parameter, callback or deletion function.

CVE / CNA score 4.3 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Wired Impact Volunteer Management
Plugin slug
wired-impact-volunteer-management
Affected
< 2.8.2
Safe version
2.8.2
Published
Aug 04, 2026
Weakness
CWE-862 — Missing Authorization

This CVE was published Aug 04, 2026 and is one of 3 known issues for this plugin.

Update, patch or deactivate.

Update Wired Impact Volunteer Management to 2.8.2 or later. Review RSVP removals by low-privilege accounts and restore unauthorized deletions from a trusted backup or source record.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Primary and upstream sources