Impact
The Eventin WordPress plugin fails to verify that a user has the necessary permissions when adding a speaker, allowing any contributor or higher-level user to create new WordPress accounts. Those accounts receive capabilities exceeding the creator’s own role, including content publishing and file uploads, and the creator can supply an email address they control to obtain a login credential for the created account. This flaw supplies a vector for attackers to establish privileged accounts that they can use to compromise the site is not a direct remote code execution flaw but results in complete elevation of authority within the WordPress installation.
Affected Systems
Eventin WordPress plugin versions prior to 4.1.24 are affected. The plugin is known under the Vendor/Product name "Eventin" and any installation running any pre-4.1.24 version is vulnerable; no other product versions are listed.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating that few attacks are expected to exploit this flaw. It is not included in the CISA KEV catalog. Based on the description, the likely attack vector involves an authenticated contributor or higher-level user interacting with the speaker creation feature. While the inherent risk is that the attacker gains elevated privileges, the low EPSS suggests that exploitation cases are currently rare, yet the potential impact remains high for any compromised site.
OpenCVE Enrichment