Executive brief
A security vulnerability exists in the Eventin plugin for WordPress, which is used to manage event registrations and schedules. An unauthorized person could exploit this flaw to access sensitive information that should be restricted to administrators. This could lead to the exposure of private event data or customer information, potentially impacting organizational privacy and compliance.
Technical details
The Eventin (formerly WP Event Solution) plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this vulnerability by sending crafted requests to affected endpoints. Successful exploitation allows the attacker to bypass intended access restrictions and retrieve sensitive data (Confidentiality: High). The vulnerability is present in versions up to and including 4.1.8. Users are advised to update to the latest available version to mitigate this risk.
Affected products
- WP Event Solution Eventin (WP Event Solution) <= 4.1.8
Timeline
- 2026-06-15: disclosed
- 2026-06-15: advisory