Impact
The Eventin WordPress plugin version prior to 4.1.20 fails to enforce proper access controls on its REST API, allowing any user with contributor-level permissions or higher to read stored customer records. This exposes sensitive personal information such as names and email addresses, creating a privacy breach that could facilitate social engineering or further credential compromise.
Affected Systems
WordPress sites running the Eventin plugin before version 4.1.20 are affected. No specific WordPress core or plugin versions beyond Eventin are listed.
Risk and Exploitability
The vulnerability can be exploited remotely by authenticated users who have contributor-level or higher privileges; the attacker needs only to craft a REST API request targeting the customer data endpoint. No known exploit in the field is reported and the EPSS score is unavailable, but the credential-based nature raises moderate to high risk for sites with many contributors. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment