Impact
The Eventin WordPress plugin version prior to 4.1.22 exposes its REST API endpoints without properly checking the status or ownership of content. This allows anyone to query draft, pending, or private posts and uncover not only the content but also passwords used to protect those posts. The flaw results in a disclosure of sensitive information to unauthenticated users, potentially revealing confidential data and login credentials. The weakness is a classic access‑control failure where content should be protected by status or ownership checks but is not, leading to data confidentiality loss.
Affected Systems
WordPress installations running the Eventin plugin before version 4.1.22 are affected. The plugin is identified as Unknown:Eventin in the CNA list. No specific WordPress core or other products are listed as affected.
Risk and Exploitability
The vulnerability can be exploited remotely by simply making a request to the vulnerable REST endpoint; no authentication or privileged status is required. The EPSS score is not available, and the issue is not yet listed in the CISA KEV catalog, indicating that no mass exploitation has been observed. Nonetheless, the flaw allows full disclosure of unpublished content and passwords, so the risk is high for sites with sensitive drafts. The likelihood of exploitation is potentially moderate because the endpoint is publicly reachable and no user interaction is needed.
OpenCVE Enrichment