Description
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabilities. This makes it possible for authenticated attackers whose account is user ID 1, even subscribers, to pass every WordPress capability check, including `manage_options`, `edit_plugins`, `edit_themes`, `promote_users`, and `update_core`, thereby elevating their privileges to administrator-equivalent power and achieving full site takeover, including remote code execution via the plugin and theme editors. Exploitation is only impactful when user ID 1 has been deliberately demoted to a lower-privilege role as a common administrator-account hardening practice; on default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Eventin plugin contains a flaw where its PermissionManager::manage_permissions() function is hooked to the map_meta_cap filter and returns 'exist' for every capability check when the current user id is 1. Because the filter is not restricted to plugin‑specific capabilities, a user who owns the user record id 1 can bypass all WordPress permission checks, gaining Administrator level rights. This allows a single subscriber account that has been demoted to, for example, Subscriber, to perform actions normally reserved for site owners such as editing plugins, changing themes, and upgrading core, providing full remote code execution.

Affected Systems

All versions of the Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin distributed by arraytics up to and including 4.1.23 are affected. The issue exists in WordPress sites that have installed the plugin with any prior release and have a demoted user 1 or have not yet applied the fix. The vulnerability is limited to environments where the map_meta_cap filter is active and the function is registered, which is the default for this plugin.

Risk and Exploitability

The CVSS base score is 7.5, indicating high severity. The EPSS score is less than 1 %, suggesting a low probability of known exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Nonetheless, because the flaw can be triggered by anyone who controls the user ID 1 account, sites that use hardening practices such as demoting the administrator account are at increased risk. An attacker would need authenticated access as user 1 to exploit this, so the attack vector is user‑privileged and requires the plugin to be installed.

Generated by OpenCVE AI on September 17, 2026 at 18:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Eventin plugin to version 4.1.24 or later where this issue is fixed.
  • If a patch is not yet available, temporarily disable or remove the map_meta_cap filter added by the plugin to prevent its override of capability checks.
  • Revoke any demotion of the user with ID 1 or restore the user to an Administrator role to avoid the privilege escalation scenario.

Generated by OpenCVE AI on September 17, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabilities. This makes it possible for authenticated attackers whose account is user ID 1, even subscribers, to pass every WordPress capability check, including `manage_options`, `edit_plugins`, `edit_themes`, `promote_users`, and `update_core`, thereby elevating their privileges to administrator-equivalent power and achieving full site takeover, including remote code execution via the plugin and theme editors. Exploitation is only impactful when user ID 1 has been deliberately demoted to a lower-privilege role as a common administrator-account hardening practice; on default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs.
Title Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-15T14:10:24.241Z

Reserved: 2026-08-18T18:27:13.284Z

Link: CVE-2026-75983

cve-icon Vulnrichment

Updated: 2026-09-15T14:10:21.184Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T07:16:29.743

Modified: 2026-09-15T15:17:21.443

Link: CVE-2026-75983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management