cleantalk
Vulnerabilities and Security Researches

Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin, CVE-2026-84905

CVE, Research URL

CVE-2026-84905

Published on
Sep 16, 2026
Research Description
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.
Affected versions
max 4.1.24.
Status
vulnerable