Skip to content

Known CVE

Eventin <= 4.0.26 - Privilege Escalation

The Eventin WordPress plugin before 4.0.27 suffers from an unauthenticated privilege escalation vulnerability. Due to a missing permission check in the a REST API endpoint, unauthenticated attackers can import users with arbitrary roles, including administrator, leading to full site compromise.

CVE-2025-47539

Critical2025CVSS 9.8CWE-269

cve2025 · wordpress · wp · wp-plugin · eventin · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website