CVE-2025-47539: WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
Published May 23, 2025
·Updated
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.
Affected Software
3 affected components
Themewinter Eventin<=4.0.26
WordPress Eventin<=4.0.26
Themewinter Eventin Wordpress<4.0.27
Remediation
Information
Update the WordPress Eventin plugin to the latest available version (at least 4.0.27).
Event History
May 23, 2025
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47539?
The severity of CVE-2025-47539 is classified as high due to its potential for privilege escalation.
2
How does CVE-2025-47539 affect users?
CVE-2025-47539 allows unauthorized users to gain elevated privileges within the Themewinter Eventin plugin.
3
Which versions of Eventin are impacted by CVE-2025-47539?
CVE-2025-47539 affects all versions of Themewinter Eventin up to and including 4.0.26.
4
How do I fix CVE-2025-47539?
To fix CVE-2025-47539, upgrade Themewinter Eventin to the latest version beyond 4.0.26.
5
Is there a workaround for CVE-2025-47539?
There are currently no known workarounds for CVE-2025-47539, and updating is the recommended action.