WordPress Plugin Vulnerabilities
Eventer <= 4.4.2 - Unauthenticated Privilege Escalation via Insecure Password Reset
Description
The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. That plaintext key can then be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any account, including administrators. Note: the reset function only works up to PHP version 7.4.
Affects Plugins
References
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Rafie Muhammad
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-07 (about 2 months ago)
Added
2026-07-07 (about 2 months ago)
Last Updated
2026-07-07 (about 2 months ago)