CVE-2025-4796: Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::updateitem' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4796?
CVE-2025-4796 is classified as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-4796?
To fix CVE-2025-4796, update the Eventin plugin to version 4.0.35 or later.
What versions of the Eventin plugin are affected by CVE-2025-4796?
CVE-2025-4796 affects all versions of the Eventin plugin up to and including version 4.0.34.
What action can attackers perform due to CVE-2025-4796?
Attackers can exploit CVE-2025-4796 to take over user accounts and escalate their privileges.
Is there a workaround for CVE-2025-4796 if I cannot update immediately?
There is no official workaround for CVE-2025-4796, so immediate updating is recommended.