Description
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
Published: 2026-08-12
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Eventin WordPress plugin before version 4.1.20 lacks an authorization check in its waiting‑list registration handler, allowing anyone on the network to create WordPress user accounts with arbitrary email addresses and to inject order records. This flaw means an attacker can quickly spin up new user accounts, potentially escalating privileges or using those accounts for further attacks or spam. The impact is a breach of account integrity and the possibility of unauthorized access to plug‑in functionality.

Affected Systems

WordPress installations that use the Eventin plugin any version prior to 4.1.20 are affected. The vulnerability is tied to the waiting‑list endpoint of the plugin.

Risk and Exploitability

The flaw can be exploited by any network user sending a crafted request to the waiting‑list endpoint; no authentication is required. While no EPSS score is available, the lack of protection and the ability to create user accounts suggest a high likelihood of exploitation, especially in environments where the plugin is exposed to the public. The vulnerability is not listed in the CISA KEV catalog at this time.

Generated by OpenCVE AI on August 12, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Eventin plugin to version 4.1.20 or later, which implements proper authorization on the waiting‑list endpoint.
  • If an upgrade cannot be performed immediately, restrict access to the waiting‑list endpoint to authenticated users only, for example by configuring web server rules or disabling the endpoint through plugin settings.
  • Verify that no pending waiting‑list requests exist from unauthenticated users and consider removing or resetting those created accounts to eliminate potential compromise.

Generated by OpenCVE AI on August 12, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
Title Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T06:00:12.053Z

Reserved: 2026-06-24T13:24:37.674Z

Link: CVE-2026-13171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T06:17:19.757

Modified: 2026-08-12T06:17:19.757

Link: CVE-2026-13171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses