THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-84901 (MEDIUM 4.9) — The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and del

[NVD] CVE-2026-84901 (MEDIUM 4.9) — The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and del

mednvdPublished 2026-09-05

CVE-2026-84901 CVSS: 4.9 MEDIUM Published: 2026-09-05T07:17:14.227

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they sho

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84901