Access violation vulnerability in Event Manager, Events Calendar, Tickets, Registrations – Eventin 4.0.4

The Eventin plugin for WordPress, which includes features such as Event Manager, Events Calendar, Tickets, and Registrations, has a security vulnerability that allows unauthorized data to be imported. This is because the ‘import_file’ function does not have a capability check in all versions up to 4.0.4. This means that attackers with Contributor-level access or higher can import events, speakers, schedules, and attendee data.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.