CVE-2025-4796

T

he Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

Configurations

Configuration 1 (hide)

cpe:2.3:a:themewinter:eventin:*:*:*:*:*:wordpress:*:*

History

13 Aug 2025, 19:31

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 19:15

Updated : 2025-08-13 19:31


NVD link : CVE-2025-4796

Mitre link : CVE-2025-4796

CVE.ORG link : CVE-2025-4796


JSON object : View

Products Affected
CWE
CWE-639

Authorization Bypass Through User-Controlled Key