GHSA-88pj-jf5h-6qhvMediumCVSS 4.9

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of...

Published
September 5, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (1)

📋 Description

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

🔗 References (3)