CVE-2026-84905
Received Received - Intake

Eventin WordPress Plugin Unauthorized Account Creation Vulnerability

Vulnerability report for CVE-2026-84905, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: WPScan

Description

The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eventin eventin to 4.1.24 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Eventin WordPress plugin before version 4.1.24 allows users with contributor-level access or higher to create new WordPress user accounts with elevated capabilities. By adding a speaker, attackers can create accounts with permissions beyond their own, such as publishing content or uploading files. They can then gain control of these accounts by using an email address they control.

Detection Guidance

Check the installed version of the Eventin plugin. If it is below 4.1.24, the system is vulnerable. Use WordPress admin panel or run: wp plugin list | grep eventin in the WordPress root directory.

Impact Analysis

If you use the Eventin plugin before version 4.1.24, an attacker with contributor-level access could escalate their privileges. They could create new accounts with higher permissions, publish unauthorized content, or upload malicious files. This could lead to website defacement, data theft, or further compromise of your WordPress site.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized account creation and privilege escalation. For GDPR, it may lead to unauthorized access to personal data. For HIPAA, it could result in unauthorized access to protected health information. Both scenarios risk violating data protection requirements.

Mitigation Strategies

Update the Eventin plugin to version 4.1.24 or later immediately. Remove unnecessary user accounts with elevated privileges and review user roles for contributors and above.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84905. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart