Impact
A vulnerability in the Eventin WordPress plugin before version 4.1.22 allows users with contributor-level privileges or higher to bypass authorization checks on several REST routes. This flaw lets an attacker change the site’s front‑page setting to an event they do not own and create, edit, or delete global event and speaker taxonomy terms that should be restricted. The result is unauthorized modification of the site’s homepage and taxonomy data, potentially leading to defacement, misrepresentation of events, and loss of control over site content.
Affected Systems
WordPress sites running the Eventin plugin version 4.1.21 or earlier. Any installation where a contributor or higher role has access is potentially affected. The vendor is listed as Unknown:Eventin, which indicates the plugin is hosted on WordPress.org or a third‑party repository.
Risk and Exploitability
The attack vector requires an authenticated contributor or higher user account and leverages the plugin’s exposed REST endpoints. Although no authentication bypass is required, an attacker who obtains contributor access can exploit the flaw to hijack the front page and manipulate taxonomies. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog; however, the absence of authorization checks indicates a high severity risk if an attacker can elevate privileges. The CVSS score is not provided, but the nature of the flaw suggests significant impact on confidentiality, integrity, and availability.
OpenCVE Enrichment