Eventin vulnerability

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

Published 5 Sep 2026Updated 5 Sep 20261 sources
CVSS 0.0

Source timeline

CVE record published by NVDView source ↗