PatchSiren

Eventin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Eventin CVE published 2026-09-09

CVE-2026-15406

The Eventin plugin for WordPress is vulnerable to Local File Inclusion, allowing authenticated attackers with custom-level access and above to execute arbitrary PHP code. This vulnerability affects WordPress administrators, security teams, and users with custom-level access, potentially leading to bypassed access controls, obtained sensitive data, or achieved code execution in cases where .php file types [truncated]

MEDIUM Eventin CVE published 2026-09-05

CVE-2026-84901

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

LOW Eventin CVE published 2026-08-21

CVE-2026-13176

The Eventin WordPress plugin, specifically versions before 4.1.21, contains a vulnerability that allows users with contributor-level access or higher to trigger blind server-side requests to arbitrary hosts. This is due to insufficient validation of user-supplied webhook URLs associated with events and a lack of event ownership verification. The vulnerability's impact is considered low, with a CVSS score [truncated]

HIGH Eventin CVE published 2026-08-19

CVE-2026-13174

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. This vulnerability has significant implications for user account security and could potentially impact the integrity of affected deployments. Administrators and users of the Eventin WordPress pl [truncated]

HIGH Eventin CVE published 2026-08-19

CVE-2026-13169

The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators. This vulnerability has significant implications for the security and integrity of events manage [truncated]

HIGH Eventin CVE published 2026-08-10

CVE-2026-13170

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. This vulnerability affects users with editor-level access and above, potentially allowing them to execute arbitrary PHP code. The plugin's failure to validate the template p [truncated]