Impact
A vulnerability in the Eventin WordPress plugin before version 4.1.22 allows users with contributor-level privileges or higher to bypass authorization checks on several REST routes. This flaw lets an attacker change the site’s front‑page setting to an event they do not own and create, edit, or delete global event and speaker taxonomy terms that should be restricted. The result is unauthorized modification of the site’s homepage and taxonomy data, potentially leading to defacement, misrepresentation of events, and loss of control over site content.
Affected Systems
WordPress sites running the Eventin plugin version 4.1.21 or earlier. Any installation where a contributor or higher role has access is potentially affected. The vendor is listed as Unknown:Eventin, which indicates the plugin is hosted on WordPress or a third‑party repository.
Risk and Exploitability
The attack vector requires an authenticated contributor or higher user account and leverages the plugin’s exposed REST endpoints. Although no authentication bypass is required, an attacker who obtains contributor access can exploit the flaw to hijack the front page and manipulate taxonomies. The EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 4.9, indicating medium severity, which still reflects a notable impact on confidentiality, integrity, and availability.
OpenCVE Enrichment