Access violation vulnerability in Events Calendar, RSVP, Booking System & Event Tickets – Eventin 4.0.34

A plugin called Eventin for WordPress has a security issue that allows people to gain more privileges by taking over another user’s account. This can happen in all versions up to and including 4.0.34. The plugin doesn’t check the user’s identity properly before allowing them to update their email. This means that people without an account can change the email address of any user, even administrators. They can then use this to reset the user’s password and access their account.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.