CVE-2026-84901
Received Received - Intake

Eventin Plugin Authorization Bypass in Event Management

Vulnerability report for CVE-2026-84901, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eventin eventin_wordpress_plugin to 4.1.22 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Eventin WordPress plugin before version 4.1.22 has a missing authorization vulnerability. Users with contributor-level access or higher can change the site's front-page setting to an event they do not own. They can also create, edit, and delete global event and speaker taxonomy terms without proper authorization.

Detection Guidance

Check your WordPress plugin version. If you are running Eventin plugin version below 4.1.22, the vulnerability is present. You can verify this via WordPress admin panel under Plugins or by checking the plugin files for version information.

Impact Analysis

An attacker with contributor-level access could alter your website's homepage to display an event they control, potentially misleading visitors. They could also modify or delete important event and speaker categories, disrupting your site's organization and content.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to modify site settings and taxonomy terms. Unauthorized changes to front-page settings or event data might expose sensitive information or alter how data is presented, which could violate data integrity and access control requirements under these regulations.

Mitigation Strategies

Update the Eventin WordPress plugin to version 4.1.22 or later immediately. This version contains the fix for the authorization vulnerability. You can update it directly from the WordPress admin panel under Plugins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84901. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart