Impact
The Eventin WordPress plugin before version 4.1.21 fails to check who owns an account or whether the requesting user has the proper capability before allowing a user account to be deleted. This flaw allows any user with a contributor‑level role or higher to permanently delete other users’ accounts. The resulting loss of user data can disrupt service for those users and erode trust in the platform.
Affected Systems
The vulnerability affects the Eventin WordPress plugin in all versions released before 4.1.21. No other WordPress core, plugin, or third‑party components are listed as affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low probability of automated exploitation. The issue is not included in the CISA KEV catalog. Attacks are inferred to be remote, carried out via the plugin’s HTTP endpoints, and require an authenticated contributor‑level or higher account. Upon successful exploitation, an attacker can delete an arbitrary user account but does not gain code execution or system‑wide access beyond this destructive capability.
OpenCVE Enrichment