๐Ÿ” CVE Alert

CVE-2026-84901

MEDIUM 4.9

Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

Vendor unknown
Product eventin
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown eventin

Be the first to know when new medium vulnerabilities affecting unknown eventin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Eventin
0 < 4.1.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b1906fd4-82ab-435f-bb07-e8f2db402029/

Credits

Sai Praneeth Koti WPScan