CVE-2026-84905
Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.
| Vendor | unknown |
| Product | eventin |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown eventin
Be the first to know when new unknown vulnerabilities affecting unknown eventin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Eventin
0 < 4.1.24
References
Credits
Karthik Ramakrishnan WPScan