WordPress Plugin Vulnerabilities

Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization

Description

The plugin does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

Proof of Concept

Affects Plugins

Fixed in 4.1.22

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 2 days ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other