Executive brief
The Eventer plugin, used for managing events on WordPress websites, contains a security flaw in how it handles password resets. This flaw allows an attacker to potentially gain full control over any user account, including administrator accounts, by accessing sensitive reset codes stored insecurely in the database. If exploited, this could lead to a complete takeover of the website, resulting in data theft or site defacement.
Technical details
The Eventer plugin for WordPress fails to securely hash password reset keys, instead storing them in plaintext within the 'eventer_verification_code' user meta field. An attacker who can read the database—for instance, by leveraging a separate SQL injection vulnerability—can retrieve these plaintext keys. These keys can then be submitted to the plugin's custom reset action to change the password for any user account. This vulnerability is particularly critical as it enables unauthenticated account takeover of administrative accounts, though the specific reset function is reportedly only functional on systems running PHP version 7.4 or lower.
Affected products
- The Eventer Eventer up to, and including, 4.4.2
Timeline
- 2026-07-08: advisory: NVD publication date