he Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
13 Aug 2025, 19:31
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-08-08 19:15
Updated : 2025-08-13 19:31
NVD link : CVE-2025-4796
Mitre link : CVE-2025-4796
CVE.ORG link : CVE-2025-4796
JSON object : View
Authorization Bypass Through User-Controlled Key