Impact
The Eventin WordPress plugin, in versions earlier than 4.1.21, fails to verify that the user making a speaker creation request has permission to edit other users. As a result, any contributor or higher role can assign arbitrary roles and modify user metadata of other accounts. This flaw provides unauthorized privilege escalation and tampering with user data. This reflects a missing authorization check (CWE-862).
Affected Systems
Affected systems are installations of the Eventin plugin on WordPress websites where the plugin version is less than 4.1.21. The vendor is listed as Unknown:Eventin. No other product versions are documented as affected.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity level, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The attack vector is likely through the regular WordPress admin interface, with an authenticated user that has contributor privileges. An attacker could create a speaker entry and thereby reassign roles, leading to potential malicious activity on the site. Based on the description, this inference is drawn because the plugin only checks user role while creating a speaker, implying an authenticated contributor can trigger it.
OpenCVE Enrichment