Impact
The Eventin plugin contains a flaw where its PermissionManager::manage_permissions() function is hooked to the map_meta_cap filter and returns 'exist' for every capability check when the current user id is 1. Because the filter is not restricted to plugin‑specific capabilities, a user who owns the user record id 1 can bypass all WordPress permission checks, gaining Administrator level rights. This allows a single subscriber account that has been demoted to, for example, Subscriber, to perform actions normally reserved for site owners such as editing plugins, changing themes, and upgrading core, providing full remote code execution.
Affected Systems
All versions of the Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin distributed by arraytics up to and including 4.1.23 are affected. The issue exists in WordPress sites that have installed the plugin with any prior release and have a demoted user 1 or have not yet applied the fix. The vulnerability is limited to environments where the map_meta_cap filter is active and the function is registered, which is the default for this plugin.
Risk and Exploitability
The CVSS base score is 7.5, indicating high severity. The EPSS score is less than 1 %, suggesting a low probability of known exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Nonetheless, because the flaw can be triggered by anyone who controls the user ID 1 account, sites that use hardening practices such as demoting the administrator account are at increased risk. An attacker would need authenticated access as user 1 to exploit this, so the attack vector is user‑privileged and requires the plugin to be installed.
OpenCVE Enrichment