Description
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Eventin WordPress plugin (versions before 4.1.21) suffers from an IDOR that allows any contributor-level user or higher to modify or delete schedule entries they do not own. This can lead to tampering of event dates, times, participants, or removal of events entirely, compromising data integrity and potentially disrupting scheduled events for other users.

Affected Systems

The vulnerability affects the Eventin WordPress plugin, all versions prior to 4.1.21. No specific version range beyond the general cutoff was provided, so any deployment of the plugin before that release is potentially impacted.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The issue is not listed in CISA KEV. An attacker only needs to possess contributor-level access or higher to abuse the flaw, typically through normal site functionality such as accessing the schedule editing interface. No elevated privileges beyond this role are required, which means that sites with many contributors are at risk of schedule tampering or deletion.

Generated by OpenCVE AI on August 20, 2026 at 16:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Eventin plugin to version 4.1.21 or later, which includes ownership verification for schedule modifications.
  • Restrict contributor users from editing or deleting schedules if your organization requires stricter access control.
  • Verify that existing schedules retain expected data integrity after the upgrade and monitor for any unintended deletions.

Generated by OpenCVE AI on August 20, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Eventin
Eventin eventin
Wordpress
Wordpress wordpress
Vendors & Products Eventin
Eventin eventin
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
Title Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
References

Subscriptions

Eventin Eventin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T12:57:42.488Z

Reserved: 2026-06-24T13:24:45.036Z

Link: CVE-2026-13175

cve-icon Vulnrichment

Updated: 2026-08-19T12:57:34.991Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:32.480

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-13175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:00:02Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key