Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 2.7epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Eventinpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/6d3bfda2-351a-4700-9fd4-4c3101bfcd38/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.