Impact
The Eventin WordPress plugin before version 4.1.20 lacks an authorization check in its waiting‑list registration handler, allowing anyone on the network to create WordPress user accounts with arbitrary email addresses and to inject order records. This flaw means an attacker can quickly spin up new user accounts, potentially escalating privileges or using those accounts for further attacks or spam. The impact is a breach of account integrity and the possibility of unauthorized access to plug‑in functionality.
Affected Systems
WordPress installations that use the Eventin plugin any version prior to 4.1.20 are affected. The vulnerability is tied to the waiting‑list endpoint of the plugin.
Risk and Exploitability
The flaw can be exploited by any network user sending a crafted request to the waiting‑list endpoint; no authentication is required. The CVSS score is 8.2. The EPSS score is < 1%, indicating a low probability of exploitation in the wild. However, because the endpoint is publicly accessible and accepts arbitrary emails, attackers can still create user accounts if they discover the flaw. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment