Impact
The Eventin WordPress plugin (versions before 4.1.21) suffers from an IDOR that allows any contributor-level user or higher to modify or delete schedule entries they do not own. This can lead to tampering of event dates, times, participants, or removal of events entirely, compromising data integrity and potentially disrupting scheduled events for other users.
Affected Systems
The vulnerability affects the Eventin WordPress plugin, all versions prior to 4.1.21. No specific version range beyond the general cutoff was provided, so any deployment of the plugin before that release is potentially impacted.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The issue is not listed in CISA KEV. An attacker only needs to possess contributor-level access or higher to abuse the flaw, typically through normal site functionality such as accessing the schedule editing interface. No elevated privileges beyond this role are required, which means that sites with many contributors are at risk of schedule tampering or deletion.
OpenCVE Enrichment