Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 2.7epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Eventinpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/f1bb2ee8-85b2-415e-ab41-97b9958e5e70/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.