Impact
The Eventin WordPress plugin contains an authorization bypass that allows an authenticated user with subscriber role or higher to perform any action on notification flow event automation workflows. Because the plugin fails to verify user permissions on the notification‑flow REST endpoint, an attacker can view, create, update, clone, or delete workflows that should be limited to administrators. This gives the attacker privileged control over automated event notifications, potentially resulting in incorrect or malicious email notifications, event scheduling changes, or denial of service to legitimate participants. The flaw is a classic example of unauthorized privilege escalation due to improper access control (CWE‑862).
Affected Systems
The affected product is arraytics Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce, a WordPress plugin. All releases up to and including 4.1.17 are vulnerable. The vulnerability originates from the notification‑flow REST API implementation in these releases.
Risk and Exploitability
The CVSS score for this issue is 5.4, indicating a medium severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires a legitimate authenticated account with subscriber privileges or higher; no external attacker‑only access is possible. Therefore the primary attack vector is internal or compromised accounts. Once authenticated, the attacker can use the API endpoint to manipulate notification flows. The lack of a publicly disclosed exploit and the need for valid credentials reduces the likelihood of widespread exploitation, but any site with active subscriber accounts remains at risk.
OpenCVE Enrichment