CVE-2026-84905: Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with Contributor-level access or a higher role can exploit it. The attacker must be able to add a speaker through the affected plugin functionality.
What does an attacker need to gain a usable elevated account?
They can supply an email address they control when creating the speaker-associated user account. This allows them to obtain a working login for the newly created account, which may have capabilities such as publishing content and uploading files.
Which plugin versions are affected?
Eventin versions before 4.1.24 are affected. Updating to version 4.1.24 or later addresses the described capability-check issue.