Description
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
Published: 2026-08-19
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Eventin WordPress plugin, in versions earlier than 4.1.21, fails to verify that the user making a speaker creation request has permission to edit other users. As a result, any contributor or higher role can assign arbitrary roles and modify user metadata of other accounts. This flaw provides unauthorized privilege escalation and tampering with user data. This reflects a missing authorization check (CWE-862).

Affected Systems

Affected systems are installations of the Eventin plugin on WordPress websites where the plugin version is less than 4.1.21. The vendor is listed as Unknown:Eventin. No other product versions are documented as affected.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity level, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The attack vector is likely through the regular WordPress admin interface, with an authenticated user that has contributor privileges. An attacker could create a speaker entry and thereby reassign roles, leading to potential malicious activity on the site. Based on the description, this inference is drawn because the plugin only checks user role while creating a speaker, implying an authenticated contributor can trigger it.

Generated by OpenCVE AI on August 20, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Eventin plugin to version 4.1.21 or later.
  • Ensure proper role validation during speaker creation, addressing the missing authorization check (CWE-862).
  • Restrict contributor role permissions or temporarily disable speaker creation for contributors.
  • Audit existing user accounts for unauthorized role changes and revert any changes identified.
  • Monitor the plugin for suspicious speaker creation activity.

Generated by OpenCVE AI on August 20, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Eventin
Eventin eventin
Wordpress
Wordpress wordpress
Vendors & Products Eventin
Eventin eventin
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
Title Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
References

Subscriptions

Eventin Eventin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T12:55:10.293Z

Reserved: 2026-06-24T13:24:41.332Z

Link: CVE-2026-13173

cve-icon Vulnrichment

Updated: 2026-08-19T12:55:06.513Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:31.960

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-13173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:00:02Z

Weaknesses