CVE-2025-4796
Last modified
CVE-2025-4796 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Themewinter | Eventin | < 4.0.35 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4796?
How severe is CVE-2025-4796?
How do I fix CVE-2025-4796?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47953Use after free in Microsoft Office allows an unauthorized at…8.4
- CVE-2025-47954Improper neutralization of special elements used in an sql c…8.8
- CVE-2025-47955Improper privilege management in Windows Remote Access Conne…7.8
- CVE-2025-47956External control of file name or path in Windows Security Ap…5.5
- CVE-2025-47957Use after free in Microsoft Office Word allows an unauthoriz…8.4
- CVE-2025-47959Improper neutralization of special elements used in a comman…7.1
- CVE-2025-47962Improper access control in Windows SDK allows an authorized …7.8
- CVE-2025-47963No cwe for this issue in Microsoft Edge (Chromium-based) all…6.5
- CVE-2025-47964Microsoft Edge (Chromium-based) Spoofing Vulnerability4.3
- CVE-2025-47966Exposure of sensitive information to an unauthorized actor i…9.8
- CVE-2025-47967Insufficient ui warning of dangerous operations in Microsoft…4.7
- CVE-2025-47968Improper input validation in Microsoft AutoUpdate (MAU) allo…7.8
Are you affected by CVE-2025-4796?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
