WordPress Plugin Vulnerabilities

Eventer <= 4.4.2 - Unauthenticated Privilege Escalation via Insecure Password Reset

Description

The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. That plaintext key can then be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any account, including administrators. Note: the reset function only works up to PHP version 7.4.

Affects Plugins

No known fix

References

Classification

Miscellaneous

Original Researcher
Rafie Muhammad
Verified
No

Timeline

Publicly Published
2026-07-07 (about 2 months ago)
Added
2026-07-07 (about 2 months ago)
Last Updated
2026-07-07 (about 2 months ago)

Other