Known CVE
Eventin <= 4.0.26 - Privilege Escalation
The Eventin WordPress plugin before 4.0.27 suffers from an unauthenticated privilege escalation vulnerability. Due to a missing permission check in the a REST API endpoint, unauthenticated attackers can import users with arbitrary roles, including administrator, leading to full site compromise.
CVE-2025-47539
Critical2025CVSS 9.8CWE-269
cve2025 · wordpress · wp · wp-plugin · eventin · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website