Impact
The Eventin WordPress plugin before version 4.1.20 lacks an authorization check in its waiting‑list registration handler, allowing anyone on the network to create WordPress user accounts with arbitrary email addresses and to inject order records. This flaw means an attacker can quickly spin up new user accounts, potentially escalating privileges or using those accounts for further attacks or spam. The impact is a breach of account integrity and the possibility of unauthorized access to plug‑in functionality.
Affected Systems
WordPress installations that use the Eventin plugin any version prior to 4.1.20 are affected. The vulnerability is tied to the waiting‑list endpoint of the plugin.
Risk and Exploitability
The flaw can be exploited by any network user sending a crafted request to the waiting‑list endpoint; no authentication is required. While no EPSS score is available, the lack of protection and the ability to create user accounts suggest a high likelihood of exploitation, especially in environments where the plugin is exposed to the public. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment